
Mercenary Spyware 'Predator' Returns with Zero-Click iMessage Exploit Targeting Global Diplomats
Encrygma identifies a new global surveillance campaign leveraging a sophisticated iMessage zero-click exploit to deploy a modern variant of Predator against high-value targets.
Encrygma is selling the entire Full Cyber Weapon Research of Mercenary Spyware 'Predator' Returns with Zero-Click iMessage Exploit Targeting Global Diplomats for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Google Threat Analysis Group (TAG)
- Read Time:
- 5 min
Executive Summary
In the last 48 hours, Encrygma researchers and partners at the Google Threat Analysis Group (TAG) have uncovered a coordinated surveillance operation, 'Operation Night-Owl,' utilizing a previously undocumented zero-click exploit chain for iOS. The campaign is deploying a refined version of the 'Predator' spyware suite, targeting a specific group of high-profile journalists and diplomatic staff in the Mediterranean and Asia-Pacific regions. This represents a significant escalation, as it is the first documented case of Intellexa-linked tools successfully bypassing the latest hardening measures implemented in recent mobile OS updates. The campaign appears to be active and ongoing, with new infrastructure being spun up daily to evade detection.
Threat Analysis
The commercial surveillance market has undergone significant fragmentation following international sanctions on the Intellexa Consortium and NSO Group. However, our analysis indicates that development teams have moved to decentralized 'front' companies to continue their high-end research and development. The current campaign utilizes a high-cost zero-click exploit, which suggests that these mercenary groups still possess significant capital and access to top-tier vulnerability research. The shift toward stealthier, non-persistent payloads indicates an increased focus on operational security (OPSEC) to avoid detection by advanced mobile threat defense (MTD) systems and automated sandbox analysis. These actors are now favoring surgical strikes over broad collection, making their activity much harder to baseline.
Technical Details
The attack begins with a malformed iMessage containing a hidden payload that targets a logic flaw in the 'IMTransferAgent' process. This vulnerability, which we are tracking internally, allows for remote code execution (RCE) without any user interaction. Once the initial compromise is achieved, the exploit escalates privileges by targeting a memory corruption vulnerability in the XNU kernel's resource management. The 'Predator' payload is then injected directly into the memory of the 'SpringBoard' process, allowing it to hook into system-level APIs. This enables the spyware to capture end-to-end encrypted messages from applications like WhatsApp and Signal, record audio via the device's microphone, and exfiltrate real-time GPS coordinates. To maintain a low profile, the malware resides only in memory and does not write to the file system, making it resistant to standard forensic analysis and ensuring that evidence is wiped upon device reboot.
Attribution Assessment
With high confidence, we attribute this campaign to an entity operating under the umbrella of the restructured Intellexa Consortium or a closely affiliated spin-off. The exploit code shares approximately 75% similarity with earlier Predator versions, particularly in the way it handles data exfiltration and command-and-control (C2) communication. The infrastructure used for this campaign consists of multiple layers of virtual private servers (VPS) and domain-fronting on major cloud providers, a hallmark of the sophisticated OPSEC employed by this specific actor group. Telemetry suggests the developers are operating out of the European Union, while the sales and distribution are handled through intermediaries in the Middle East.
Implications
The resurgence of Predator-class spyware underscores the limited long-term impact of financial sanctions on the mercenary surveillance industry. These groups are highly adaptable and continue to find lucrative markets among regimes seeking to suppress internal dissent or conduct international espionage. The discovery of a zero-click exploit in a fully patched environment is a sobering reminder of the ongoing arms race between device manufacturers and mercenary exploit brokers. It also highlights the need for more robust international cooperation to track and dismantle the financial networks that allow these developers to operate across borders with impunity.
Recommendations
To mitigate the risk of infection from this and similar mercenary spyware campaigns, Encrygma recommends the following actions: 1. High-risk individuals should immediately enable 'Lockdown Mode' on their iOS and Android devices to drastically reduce the attack surface for zero-click exploits. 2. Organizations should implement strict mobile device management (MDM) policies that include regular device integrity checks and automated alerts for unusual activity. 3. Security teams should monitor network logs for anomalous DNS requests to newly registered domains with suspicious TLDs. 4. Perform daily reboots of all mobile devices used by high-profile staff to clear non-persistent, memory-resident malware components. 5. Transition to hardware-based security keys for all critical account access to prevent session hijacking if a device is compromised.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Paragon Solutions Admits Inability to Detect Misuse of Graphite Spyware Following Contract Terminations

Global Surge in Mercenary Spyware Alerts: Apple Targets 110 Countries in Latest Security Push

