
criticalOffensive Tools
Intellexa Alliance Resurfaces with 'Predator-X' Zero-Click Exploits Targeting iOS and Android
Researchers have identified a new mercenary spyware campaign by the Intellexa Alliance. Dubbed 'Predator-X', the tool uses zero-click exploits to target diplomats and activists globally.
28 July 2026Last updated 20 August 20265 min readGoogle Threat Analysis Group (TAG)
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Middle East and Europe
- Confidence:
- High Confidence
- CVE:
- CVE-2026-9921
- Source:
- Google Threat Analysis Group (TAG)
- Read Time:
- 5 min
Executive Summary\n\nIn a critical development observed over the past 24 hours, security researchers at Encrygma, in collaboration with the Google Threat Analysis Group (TAG), have uncovered a widespread surveillance campaign utilizing a new iteration of the 'Predator' spyware, now referred to as 'Predator-X'. This campaign, orchestrated by the Intellexa Alliance, represents a significant escalation in the capabilities of mercenary spyware. The tools are currently being deployed against high-profile targets, including diplomatic staff and civil society leaders, primarily located in the Mediterranean region, Western Europe, and parts of the Middle East. The discovery highlights the persistent threat posed by commercial surveillance entities that operate with high levels of technical sophistication, consistently staying ahead of defensive mitigations.\n\n## Threat Analysis\n\nThe Predator-X spyware is a modular, cross-platform surveillance tool designed for comprehensive data extraction from both iOS and Android devices. The current campaign is characterized by its use of a sophisticated zero-click exploit chain, meaning the target requires no interaction—such as clicking a link or opening a file—for the infection to occur. The primary objective appears to be political espionage and the monitoring of strategic communications. By gaining full control over the target's mobile device, the attackers can access end-to-end encrypted messages, private emails, photos, and live microphone and camera feeds, effectively turning the device into a persistent, portable bugging tool. The selection of targets suggests a state-sponsored client base seeking intelligence on regional geopolitical shifts and internal dissent.\n\n## Technical Details\n\nThe 'Predator-X' infection sequence begins with the delivery of a malicious payload via a zero-day vulnerability in the WebKit engine and the operating system's handling of specific media formats. The initial vector is often an invisible, multi-part message delivered through encrypted communication apps. Upon processing the malicious attachment, the exploit triggers a remote code execution (RCE) in a sandboxed process. To escape the sandbox, the spyware leverages a separate vulnerability, designated CVE-2026-9921, to achieve kernel-level privileges by exploiting a race condition in the virtual memory subsystem. Once the kernel is compromised, the main spyware module is loaded directly into the device's RAM. This memory-only residence makes traditional forensic analysis and detection extremely difficult, as no persistent files are written to the disk until a persistence module is optionally deployed. The C2 (Command and Control) infrastructure utilizes a multi-tiered proxy system to mask the final destination of the exfiltrated data, employing advanced domain-fronting techniques on major cloud providers to blend in with legitimate enterprise web traffic.\n\n## Attribution Assessment\n\nBased on forensic artifacts and infrastructure analysis, Encrygma attributes this activity to the Intellexa Alliance (comprising Cytrox and Intellexa) with high confidence. The 'Predator-X' code exhibits significant structural and functional overlap with previously documented versions of the Predator spyware. Furthermore, the TTPs (Tactics, Techniques, and Procedures) observed in the C2 setup, including the use of specific server configurations and naming conventions for domains, are consistent with the known operations of the Intellexa group. The targeting patterns also align with the historical client base and geopolitical interests associated with the alliance's known customers in the region.\n\n## Implications\n\nThe emergence of 'Predator-X' underscores a worrying trend in the commodification of high-end cyber-offensive capabilities. As commercial entities continue to develop and sell zero-click exploits, the barrier to entry for sophisticated digital surveillance is lowered for both state and non-state actors. This proliferation poses a severe threat to international security, press freedom, and the privacy of individuals worldwide. The ability of these firms to rapidly iterate their tools in response to security patches suggests a well-funded and highly capable research and development ecosystem that rivals top-tier nation-state intelligence agencies. This creates a continuous arms race between spyware developers and mobile OS vendors.\n\n## Recommendations\n\nTo mitigate the risk of infection by mercenary spyware like Predator-X, users are urged to: 1. Update all mobile devices to the latest OS versions immediately. 2. Enable 'Lockdown Mode' on iOS devices, which significantly reduces the attack surface by disabling high-risk features like link previews and specific JIT compilations. 3. Be cautious of unsolicited messages, even on encrypted platforms. 4. Use hardware-based security keys for all sensitive accounts to prevent secondary credential theft. 5. Organizations should implement robust Mobile Device Management (MDM) policies and conduct regular security audits for high-risk personnel who may be targeted by such sophisticated actors.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room