Researchers find Predator spyware is being used in several countries, including Iraq
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户的要求是直接写文章描述,不需要特定的开头。 首先,我得仔细阅读这篇文章。文章主要讲的是间谍软件开发商Intellexa的情况。根据Insikt Group的研究,2025年使用其Predator间谍软件的活动有所减少,但可能是因为域名变化让检测更难了。 接下来,文章提到Intellexa的客户分布在沙特、哈萨克斯坦等国,而埃及等国的活动停止了。这可能意味着客户不再使用或改变了基础设施。此外,发现了与Intellexa相关的多家新公司,涉及产品运输和广告行业。 还有,美国商务部在2023年将Intellexa列入实体名单,并制裁了创始人Tal Jonathan Dilian和其他相关人士。这些制裁是因为担心他们对美国国家安全构成风险。 总结时要抓住关键点:活动放缓、客户分布变化、新公司关联、美国制裁。确保信息准确且简洁。 </think> 文章指出间谍软件开发商Intellexa的活动在2025年有所放缓,但其客户分布于沙特、哈萨克斯坦等地,同时发现与该公司相关的多家新公司。美国此前已对该公司及其创始人实施制裁。 2025-12-4 13:1:21 Author: therecord.media(查看原文) 阅读量:5 收藏

Use of spyware from a developer sanctioned by the U.S. last year appears to have slowed in 2025, though it is possible that changes in domain naming conventions may be masking increased activity by making it harder for experts to detect infrastructure, according to new research.

New evidence suggests that the company, Intellexa, is also currently being deployed in Iraq, according to the report from Recorded Future’s Insikt Group. The Record is an editorially independent unit of Recorded Future.

Researchers also found indicators “likely associated” with the use of Predator spyware by an entity tied to Pakistan. It is unclear if this activity involved targets within or tied to Pakistan or if a customer was operating from inside Pakistan, the report says. 

Intellexa manufactures Predator spyware, which has been used against members of civil society and business executives worldwide. Three former Intellexa executives are currently on trial in Greece, where scores of victims of Predator spying are located.

Researchers found evidence of Intellexa customers currently operating in Saudi Arabia, Kazakhstan, Angola and Mongolia, the report said. Meanwhile, the report said, it appears that customers in Egypt, Botswana and Trinidad and Tobago have “ceased communication” as of this spring and summer.

That could indicate customers are no longer using Intellexa in those countries or that they changed their infrastructure setups, the report said.

A Mozambique-linked cluster discovered by Insikt earlier this year remained operative until at least late June 2025, the report says.

The report builds on earlier research Insikt released on Intellexa in June — the spyware maker has changed its infrastructure setups as a result of increased scrutiny in recent years, making detection more difficult. 

Researchers also found several new companies believed to be tied to Intellexa, which like other spyware vendors has long obfuscated its activities by hiding operations inside shell companies and complex webs of interconnected firms.

At least one of the newly-detected companies appears to be charged with shipping Intellexa products to clients, the report says. Two other newly-identified companies are believed to be in the advertising sector and may be connected to a known threat vector which uses ads to deliver spyware.

Two more companies linked to Intellexa were found in Kazakhstan and the Philippines, the report says. The findings indicate an “expanding network footprint,” according to the report.

In July 2023, the Commerce Department placed Intellexa on its Entity List, which identifies organizations or individuals believed to pose risks to the national security or foreign policy interests of the United States.

In March 2024, Commerce sanctioned company founder Tal Jonathan Dilian, a former Israeli intelligence officer. Six months later, five more people and one entity linked to Intellexa were also sanctioned.

Senior administration officials told reporters at the time that more action was needed to target the company’s “opaque web of corporate entities, which are designed to avoid accountability.”

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.


文章来源: https://therecord.media/intellexa-predator-spyware-continues-despite-sanctions
如有侵权请联系:admin#unsafe.sh