Predator much smarter than we thought

Predator spyware from Intellexa gathers valuable data even from failed attacks and specifically targets IT security researchers.

A new study from the team Jamf Threat Labs, an Apple expert, paints a picture of malware whose technical level far exceeds anything we thought. Its developers are said to have implemented features that go beyond simple espionage. The malicious application actively defends itself from detection and learns from mistakes.

See more articles from iGuRu.gr when you search for news on Google.

A crucial aspect of the new findings concerns Predator's behavior in moments of failure or when it detects detection. According to Jamf experts, a highly specialized "kill switch" has been documented that goes far beyond simple self-deletion routines. This feature, they say, serves as an ultimate shield against security researchers.

If the spyware detects that it is running in an analysis environment or if certain iPhone security mechanisms are activated, its programming indicates that it will activate the “kill switch.” This doesn’t just erase its tracks. The software intentionally shuts down its operation to hide its valuable exploits and communication channels from the eyes of forensic analysts.

This defensive strategy is complemented by a precise diagnostic system. Jamf was able to document a complete classification of error codes ranging from 301 to 311. These codes act as feedback channels for attackers. If an infection attempt fails or the kill switch is triggered, the spyware automatically sends an encrypted status message back to the control servers.

This way, attackers learn exactly which security measure or researcher tools triggered the detection. This feedback system turns every successful defense response of an operating system into a source of information with which attackers can improve their tools for the next attempt.

In addition to this learning ability, Predator has built further defenses against analysis by security researchers. Experts have discovered features to actively monitor processes looking for traces of debug kits or suspicious root CA certificates. The latter are often used in computer forensics to decrypt data traffic.

Comparison with NSO Group's Pegasus

The findings highlight the professionalism of the Intellexa Alliance and, according to the researchers, show that the line between government agencies and commercial spyware providers is technologically almost non-existent. Predator is not a static tool but a dynamically adapting system.

Compared to the notorious NSO Group state-sponsored Pegasus trojan, which often infects devices via zero-click exploits without any user interaction, Predator relies primarily on one-click attacks via pre-packaged links. Technically, both platforms are considered equivalent in the scope of their functionality for spying on microphones, cameras, and encrypted conversations. However, Pegasus is primarily optimized for maximum invisibility and silent infiltration. Predator stands out for its aggressive anti-analysis techniques. The program appears to be designed to proactively combat the security community.

In 2024, the administrators of the platform for delivering and controlling the powerful Predator were forced to shut down several servers. The strategy of human rights organizations and security researchers to name and expose the black sheep in the state-sponsored trojan industry seemed to be at least temporarily successful.

The US government tightened sanctions against the group at the time and personally targeted Intellexa founder Tal Dilian and his right-hand man, Sara Hamou.

The Intellexa Alliance is considered a consortium of dubious European companies that supplies cyberweapons not only to dictators.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).