Predator spyware used to infect phone belonging to Angolan journalist, report says
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我得仔细阅读文章内容,抓住主要信息。 文章讲的是一个安哥拉记者Teixeira Cândido的手机被Predator间谍软件感染了,这是该软件在安哥拉的首次记录。Amnesty International发布的报告提到,尽管Predator的制造商Intellexa Consortium在2023年被美国政府列入实体名单,但他们仍在暗中活动。此外,拜登政府对Intellexa的高管进行了制裁,但特朗普政府又解除了部分制裁。 Predator间谍软件被多国政府滥用,用于攻击社会领袖。Cândido是在点击了一个伪装成学生发送的恶意链接后感染的。Amnesty International通过取证分析确认了这一点,并指出攻击者使用了社会工程学手段。 总结的时候要包括:记者被感染、工具名称、制造商的情况、制裁信息、攻击手段以及结果。控制在100字以内,所以需要简洁明了。 可能的结构:安哥拉记者手机感染Predator间谍软件,Amnesty报告指出这是首例;尽管制造商被制裁仍在运营;攻击者伪装成学生发送恶意链接;该软件被多国滥用。 </think> 一位安哥拉记者Teixeira Cândido的手机于2024年5月感染了Predator间谍软件,这是该工具在安哥拉的首例记录。尽管制造商Intellexa Consortium因被列入美国实体名单而受到限制,但其仍继续运营。攻击者伪装成学生发送恶意链接,导致感染。该间谍软件被多国滥用以 targeting 社会领袖。 2026-2-18 14:31:41 Author: therecord.media(查看原文) 阅读量:1 收藏

A phone belonging to a prominent Angolan journalist and press freedom advocate was infected with Predator spyware in May 2024, marking the first documented instance of the tool’s use in the country, according to a report released Wednesday by Amnesty International.

The finding is the latest evidence that despite being placed on the U.S. government’s Entity List in July 2023, Predator manufacturer the Intellexa Consortium has continued to operate in the shadows. Being placed on the Entity List imposes strict licensing and other requirements on companies attempting to do business in the U.S. and can be crippling to companies’ overall operations.

Intellexa executives and consultants also were sanctioned by the Biden administration in September 2024, but the Trump administration delisted three of them in December.

Predator is a powerful spyware that has been abused by governments worldwide to target civil society leaders. In October 2023, Amnesty International and partner organizations published the Predator Files, an investigation which showed that Predator had been used to target the president of the European Parliament, the president of Taiwan and U.S. officials, among many others.

The Angolan journalist whose phone was infected, Teixeira Cândido, told Amnesty he feels “naked knowing that I was the target of this invasion of my privacy. I don’t know what they have in their possession about my life.” It is unclear who is behind the attack, Amnesty said in a press release.

Cândido received several WhatsApp messages on his iPhone from an unknown Angolan number from April to June 2024, Amnesty said. He clicked on a malicious link on May 4 and Predator was installed. The spyware was removed later that evening when the phone was restarted.

The attacker sent 11 more infection links in the following weeks, Amnesty said, but they all failed because they weren’t opened.

Forensic traces of the installation along with known Predator infection domains used in the infection links led Amnesty researchers to attribute the attack to Predator.

The attacker used social engineering techniques to get Cândido to click on the link by pretending to be a student interested in Angolan social and economic affairs, according to Amnesty.

After initially “building rapport,” the press release said, the attacker sent a series of links which pretended to “direct to news and seemingly genuine websites."

In December 2025, Amnesty researchers found a device belonging to a human rights lawyer in Pakistan’s Balochistan province had been targeted with Predator via links sent through WhatsApp during the summer of 2025.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/predator-spyware-used-to-infect-phone-angola-journalist
如有侵权请联系:admin#unsafe.sh