News Room
16
Share
Mercenary Spyware 'Predator' Updated with AI-Accelerated Zero-Click Exploits and Stealth HAL Modules
criticalOffensive Tools

Mercenary Spyware 'Predator' Updated with AI-Accelerated Zero-Click Exploits and Stealth HAL Modules

New reports from Citizen Lab and Jamf Threat Labs identify a sophisticated upgrade to the Predator spyware framework. The update features zero-click delivery and the ability to suppress OS privacy indicators during surveillance.

12 July 2026Last updated 20 August 20265 min readCitizen Lab & Jamf Threat Labs
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Europe
Confidence:
High Confidence
Source:
Citizen Lab & Jamf Threat Labs
Read Time:
5 min

Executive Summary

On July 11, 2026, cybersecurity researchers from Citizen Lab and Jamf Threat Labs released a joint technical advisory regarding a new, highly advanced iteration of the 'Predator' mercenary spyware. This update, linked to the Intellexa Alliance, has been detected in a coordinated campaign targeting members of the European Parliament and high-profile investigative journalists in the Mediterranean region. The most alarming development is the integration of a 'Stealth-HAL' module, which allows the spyware to operate the device’s camera and microphone without triggering the operating system's hardware privacy indicators (the green and orange dots). Encrygma's internal monitoring confirms that this campaign leverages several previously unpatched vulnerabilities in modern mobile operating systems, including iOS 26 and Android 16.

Threat Analysis

The current campaign, dubbed 'SilentSentry,' represents a significant leap in the offensive capabilities of private-sector surveillance firms. Unlike previous iterations that required a 'one-click' interaction via a phishing link, SilentSentry utilizes a 'zero-click' delivery mechanism. This mechanism is delivered through the processing of malformed Rich Communication Services (RCS) messages and iMessage attachments, requiring no user interaction. The targets identified thus far are exclusively high-value individuals involved in corruption investigations and human rights advocacy. The use of these tools suggests that despite international sanctions, the mercenary spyware market is not only surviving but innovating rapidly to bypass hardened mobile security architectures.

Technical Details

Technical analysis of the exploit chain reveals a three-stage process. The first stage involves a remote code execution (RCE) vulnerability in the WebKit and Chrome V8 engines, specifically targeting how they handle AI-generated media codecs. This is followed by a kernel-level privilege escalation that utilizes a race condition in the OS's memory management subsystem. The third and most critical stage is the deployment of the 'Stealth-HAL' module. This module hooks into the Hardware Abstraction Layer (HAL) and intercepts system calls to the Media Capture Service. By injecting malicious code into the system's trust zone, the spyware can silenty stream audio and video data while simultaneously sending 'false-negative' signals to the OS's privacy notification daemon. Furthermore, the malware utilizes an AI-driven command-and-control (C2) protocol that adapts its traffic patterns to mimic legitimate encrypted applications, such as WhatsApp or Signal, making network-level detection extremely difficult.

Attribution Assessment

Encrygma attributes this activity with high confidence to the Intellexa Alliance. Forensic artifacts found in the C2 infrastructure show significant overlaps with previous 'Predator' clusters identified in 2024 and 2025. Specifically, the use of unique cryptographic obfuscation routines and domain naming conventions points to the same development team. While the entities involved have rebranded multiple times to evade US and EU sanctions, the underlying codebase remains a direct evolution of the Cytrox-developed Predator framework. There are also indications that a Mediterranean-based exploit broker, recently surfaced under the name 'Vanguard Systems,' is facilitating the sale of these new zero-click modules to nation-state clients.

Implications

The ability to suppress hardware privacy indicators marks a critical failure in current mobile security paradigms. These indicators were designed to be the 'last line of defense' for user awareness. The successful circumvention of these alerts by commercial spyware indicates that software-based trust boundaries are increasingly insufficient against state-level offensive research. Furthermore, the use of AI to accelerate the discovery of these zero-day flaws has shortened the 'patch-gap,' leaving defenders with less time to respond to emerging threats. This poses a severe risk to democratic institutions and the confidentiality of sensitive diplomatic communications.

Recommendations

Encrygma recommends that all organizations with high-risk personnel immediately mandate the use of 'Lockdown Mode' (iOS) and 'Advanced Protection' (Android). These modes significantly reduce the attack surface by disabling the complex media processing features often targeted by zero-click exploits. Additionally, security teams should implement Mobile Threat Defense (MTD) solutions that monitor for unauthorized modifications to system-level binaries and HAL services. For individuals at extreme risk, regular hardware-level audits and the use of physical privacy covers for cameras are advised. Frequent device reboots (at least once every 12 hours) can help disrupt non-persistent exploit stages, though they do not guarantee full remediation of a kernel-level infection.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo