News Room
16
Share
Mercenary Spyware 'Predator' Returns with Zero-Click iMessage Exploit Targeting Global Diplomats
criticalOffensive Tools

Mercenary Spyware 'Predator' Returns with Zero-Click iMessage Exploit Targeting Global Diplomats

Encrygma identifies a new global surveillance campaign leveraging a sophisticated iMessage zero-click exploit to deploy a modern variant of Predator against high-value targets.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Mercenary Spyware 'Predator' Returns with Zero-Click iMessage Exploit Targeting Global Diplomats for ₿ 0.10 BTC. Contact us.

09 July 2026Last updated 20 August 20265 min readGoogle Threat Analysis Group (TAG)
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
Source:
Google Threat Analysis Group (TAG)
Read Time:
5 min

Executive Summary

In the last 48 hours, Encrygma researchers and partners at the Google Threat Analysis Group (TAG) have uncovered a coordinated surveillance operation, 'Operation Night-Owl,' utilizing a previously undocumented zero-click exploit chain for iOS. The campaign is deploying a refined version of the 'Predator' spyware suite, targeting a specific group of high-profile journalists and diplomatic staff in the Mediterranean and Asia-Pacific regions. This represents a significant escalation, as it is the first documented case of Intellexa-linked tools successfully bypassing the latest hardening measures implemented in recent mobile OS updates. The campaign appears to be active and ongoing, with new infrastructure being spun up daily to evade detection.

Threat Analysis

The commercial surveillance market has undergone significant fragmentation following international sanctions on the Intellexa Consortium and NSO Group. However, our analysis indicates that development teams have moved to decentralized 'front' companies to continue their high-end research and development. The current campaign utilizes a high-cost zero-click exploit, which suggests that these mercenary groups still possess significant capital and access to top-tier vulnerability research. The shift toward stealthier, non-persistent payloads indicates an increased focus on operational security (OPSEC) to avoid detection by advanced mobile threat defense (MTD) systems and automated sandbox analysis. These actors are now favoring surgical strikes over broad collection, making their activity much harder to baseline.

Technical Details

The attack begins with a malformed iMessage containing a hidden payload that targets a logic flaw in the 'IMTransferAgent' process. This vulnerability, which we are tracking internally, allows for remote code execution (RCE) without any user interaction. Once the initial compromise is achieved, the exploit escalates privileges by targeting a memory corruption vulnerability in the XNU kernel's resource management. The 'Predator' payload is then injected directly into the memory of the 'SpringBoard' process, allowing it to hook into system-level APIs. This enables the spyware to capture end-to-end encrypted messages from applications like WhatsApp and Signal, record audio via the device's microphone, and exfiltrate real-time GPS coordinates. To maintain a low profile, the malware resides only in memory and does not write to the file system, making it resistant to standard forensic analysis and ensuring that evidence is wiped upon device reboot.

Attribution Assessment

With high confidence, we attribute this campaign to an entity operating under the umbrella of the restructured Intellexa Consortium or a closely affiliated spin-off. The exploit code shares approximately 75% similarity with earlier Predator versions, particularly in the way it handles data exfiltration and command-and-control (C2) communication. The infrastructure used for this campaign consists of multiple layers of virtual private servers (VPS) and domain-fronting on major cloud providers, a hallmark of the sophisticated OPSEC employed by this specific actor group. Telemetry suggests the developers are operating out of the European Union, while the sales and distribution are handled through intermediaries in the Middle East.

Implications

The resurgence of Predator-class spyware underscores the limited long-term impact of financial sanctions on the mercenary surveillance industry. These groups are highly adaptable and continue to find lucrative markets among regimes seeking to suppress internal dissent or conduct international espionage. The discovery of a zero-click exploit in a fully patched environment is a sobering reminder of the ongoing arms race between device manufacturers and mercenary exploit brokers. It also highlights the need for more robust international cooperation to track and dismantle the financial networks that allow these developers to operate across borders with impunity.

Recommendations

To mitigate the risk of infection from this and similar mercenary spyware campaigns, Encrygma recommends the following actions: 1. High-risk individuals should immediately enable 'Lockdown Mode' on their iOS and Android devices to drastically reduce the attack surface for zero-click exploits. 2. Organizations should implement strict mobile device management (MDM) policies that include regular device integrity checks and automated alerts for unusual activity. 3. Security teams should monitor network logs for anomalous DNS requests to newly registered domains with suspicious TLDs. 4. Perform daily reboots of all mobile devices used by high-profile staff to clear non-persistent, memory-resident malware components. 5. Transition to hardware-based security keys for all critical account access to prevent session hijacking if a device is compromised.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo