News Room
16
Share
Israeli State Intervention Blocks Pegasus Evidence as Predator Spyware Diversifies Global Operations
criticalOffensive Tools

Israeli State Intervention Blocks Pegasus Evidence as Predator Spyware Diversifies Global Operations

Recent leaks confirm the Israeli government seized NSO Group files to obstruct U.S. legal discovery, while Intellexa’s Predator expands into West Africa and targets European leadership.

25 July 2026Last updated 20 August 20264 min readGuardian / Citizen Lab / Encrygma Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
Source:
Guardian / Citizen Lab / Encrygma Intelligence
Read Time:
4 min

Executive Summary

On July 25, 2026, new intelligence confirms that the Israeli government has taken unprecedented steps to shield the NSO Group from legal discovery in the United States. Concurrently, technical analysis of the mercenary spyware market reveals that the Intellexa Consortium has significantly expanded its footprint despite ongoing international sanctions. These developments represent a critical escalation in the state-sponsored surveillance landscape, where the intersection of private profit and national security interests continues to frustrate regulatory and legal efforts to curb human rights abuses. This report analyzes the recent legal obstruction regarding Pegasus and the technical evolution of the Predator spyware suite.

Threat Analysis

The mercenary spyware market is undergoing a period of resilient diversification. While NSO Group remains under heavy legal and financial pressure, the Israeli government's intervention—secretly seizing documents and computer systems from NSO to prevent their transfer to U.S. courts—highlights a strategic move to protect national cyber capabilities at the expense of international legal transparency. Meanwhile, the Intellexa Consortium (creators of Predator) has successfully pivoted its infrastructure. Despite 2024-2025 sanctions, Intellexa has established new front companies in jurisdictions like Kazakhstan and the Philippines, utilizing a web of corporate entities that include everything from skincare firms to digital marketing agencies to obfuscate their financial trails.

Technical Details

Recent forensic investigations by Citizen Lab and Encrygma researchers have identified the persistent use of the "WhatsApp Installation Server" (WIS) by NSO clients. The WIS architecture allows operators to send "cipher" files containing installation vectors that trigger zero-click infections. In the latest campaigns targeting European Union officials, researchers observed a transition toward a hybrid infection model. This involves the "Aladdin" ad-based infection vector, which uses malicious advertisements to redirect mobile browsers to exploit servers without user interaction. Once the initial payload is delivered, the spyware leverages previously unpatched vulnerabilities in image processing libraries—specifically targeting the DNG file format—to escalate privileges and gain full persistence on both iOS and high-end Android devices. These exploits demonstrate an advanced capability to bypass the latest iterations of "Lockdown Mode" on mobile platforms.

Attribution Assessment

The current surge in surveillance activity is attributed to two primary clusters. The first is the well-documented NSO Group, whose Pegasus tool remains the benchmark for sophisticated mobile intrusion. The second is the Intellexa Consortium, led by former Israeli intelligence officer Tal Dilian. Attribution for the latest European Parliament targeting points toward a "MERCENARY-APT" cluster that overlaps with historical campaigns linked to Middle Eastern and North African intelligence agencies. Specifically, codenames such as "Subaru" (linked to Saudi Arabia) and "Morgan" (linked to Morocco) have reappeared in network telemetry associated with the recent targeting of MEP Stelios Kouloglou.

Implications

The inability of the U.S. court system to compel discovery from NSO Group due to foreign state intervention sets a dangerous precedent. It suggests that mercenary vendors can operate with a level of sovereign immunity if their home states deem the technology vital to national interests. Furthermore, the expansion of Intellexa into regions like Angola and Pakistan indicates that the market for offensive cyber tools is not only surviving sanctions but thriving in emerging markets where oversight is minimal. This creates an environment where journalists, activists, and diplomats are perpetually at risk of high-level compromise.

Recommendations

  1. Hardware Isolation: High-risk individuals should utilize secondary, non-persistent mobile devices for sensitive communications and implement physical privacy covers for cameras and microphones.
  2. Enhanced Monitoring: Security Operations Centers (SOCs) must implement mobile-specific EDR solutions and monitor for unusual network egress to known spyware infrastructure (IP blocks associated with Intellexa's new ad-based redirection servers).
  3. Protocol Hardening: Disable the processing of non-essential file formats (like DNG or TIFF) in messaging applications where possible.
  4. Policy Advocacy: Organizations should support legislative efforts that target the entire corporate ecosystem of mercenary firms, including the reselling and training partners that facilitate global proliferation.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo