logo

Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue

ID: b49b2667-565a-544b-b1d2-e0bb50e56ee2

STIX ID: report--b49b2667-565a-544b-b1d2-e0bb50e56ee2

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-12-03

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

This report details Intellexa’s sophisticated multi-stage exploit and spyware campaign that leverages V8/Chrome vulnerabilities (including CVE-2025-6554) and iOS kernel bugs (CVE-2023-41991, CVE-2023-41992) to achieve full device compromise; it describes the exploit chain (leak primitives, sandbox escape, helper/watcher modules), delivery methods (targeted one-time links and malicious ads), detection avoidance techniques, and shared IOCs and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.