What is Predator spyware?
Predator is a commercial mobile spyware product developed by Cytrox and sold under the Intellexa banner, used to covertly surveil iOS and Android devices. Marketed almost exclusively to government and intelligence customers, Predator has been used to target journalists, politicians, academics, and activists, and it is widely regarded as one of the most capable mercenary spyware tools alongside NSO Group's Pegasus. Once installed, it can record calls and audio, read messages from encrypted apps, and exfiltrate a wide range of personal data. Because it is sometimes called "Predator malware," the two terms refer to the same Intellexa product. Predator has been documented extensively by researchers at Google's Threat Analysis Group, Citizen Lab, Cisco Talos, and Amnesty International, and it has drawn US government sanctions. This page explains what Predator is, who builds it, how it infects devices, who it has targeted, the regulatory response, and how at-risk users and organizations can reduce their exposure. It also clarifies one important naming point: Predator spyware is not the same as "Predator the Thief," an unrelated Windows infostealer.
Key takeaways
- Commercial mercenary spyware. Predator is developed by Cytrox and sold by the Intellexa alliance to government clients for mobile surveillance.
- One-click and zero-click delivery. It infects iOS and Android through exploit chains that often rely on zero-day vulnerabilities, and can persist across reboots.
- High-value targets only. Documented targets include journalists, politicians, academics, and activists, not the general public.
- Sanctioned by the US government. Cytrox and Intellexa were added to the US Entity List in 2023, and OFAC imposed further sanctions on the consortium and key individuals in 2024.
- "Predator spyware" and "Predator malware" are the same thing. "Predator the Thief" is a separate, unrelated Windows infostealer.
Who builds Predator: Cytrox and the Intellexa alliance
Predator originated with Cytrox, a company established in North Macedonia in 2017 that initially built Android malware. Cytrox was acquired in 2018 and folded into a broader commercial-surveillance grouping assembled by Tal Dilian, a former Israeli military intelligence officer. In 2019, that grouping became the Intellexa alliance, a marketing label uniting several surveillance vendors, and Predator became its flagship spyware product.
Intellexa positions itself as an EU-based, regulated company and competes directly with NSO Group in the mercenary-spyware market. Leaked commercial proposals reported by journalists put the price of a Predator deployment in the millions of euros, which underlines that this is a tool built for well-resourced state customers rather than ordinary criminals. Investigations such as the 2023 "Predator Files," led by the European Investigative Collaborations network, mapped the consortium's corporate structure and reported sales to more than two dozen countries.
How Predator spyware works
Predator is a modular mobile spyware suite rather than a single file. Security researchers, notably Cisco Talos, have described two core components that work together: a loader known as ALIEN and the main implant, PREDATOR. ALIEN establishes the low-level access PREDATOR needs, while PREDATOR delivers Python-based modules so new capabilities can be added without re-exploiting the device.
Infection and delivery
Predator has been delivered through both one-click and zero-click methods. In one-click campaigns, a target receives a link over email, SMS, or a messaging app such as WhatsApp; clicking it briefly routes them through an exploit page before landing on a legitimate site, making the infection invisible. More advanced delivery has used zero-click exploits and network injection, where a privileged position on the mobile network inserts exploit code directly into a target's web traffic without any interaction. Google's Threat Analysis Group documented Predator campaigns exploiting multiple Chrome and Android zero-day vulnerabilities. On iOS, Predator has abused the Shortcuts automation feature to reinstall itself, giving it persistence across reboots depending on the customer's licensing tier.
Capabilities
Once active, Predator provides comprehensive surveillance. Documented capabilities include recording phone calls and audio from VoIP apps, reading messages from encrypted applications such as Signal, WhatsApp, and Telegram, harvesting contacts and stored data, and activating the microphone. It is engineered to be difficult to detect: it has spoofed legitimate process names, evaded antivirus, and, according to 2026 research by Jamf, includes granular anti-analysis logic that detects when a device is in a researcher-friendly state such as iOS Developer Mode.
Predator vs Pegasus
Predator is frequently compared to Pegasus, and the two are the best-known products in the mercenary-spyware market. They share a business model and an outcome, targeted government surveillance of mobile devices, but come from different vendors.
The practical takeaway is that Predator and Pegasus are peers, not variants of each other. For defenders and at-risk individuals, the mitigations overlap heavily, because both rely on mobile exploit chains and both serve the same kind of targeted surveillance.
Who Predator has targeted
Predator is not mass-market malware; its use has consistently focused on high-value individuals of interest to state customers. Citizen Lab documented its use against exiled Egyptian politician Ayman Nour in 2021, and reporting on a major case in Greece described dozens of targeted devices belonging to journalists, politicians, and business figures. The broader "Predator Files" investigation reported that the tooling had been sold to a long list of countries. Meta has acted against the operators, removing hundreds of accounts linked to Cytrox that were used for reconnaissance and to deliver malicious links. This targeting pattern, journalists, opposition politicians, and activists, is what places commercial spyware like Predator at the center of digital-rights and human-rights concerns.
Sanctions and regulatory response
Predator and its makers have faced escalating government action. In 2023, the US Department of Commerce added Cytrox and Intellexa entities to its Entity List, restricting their access to US technology. In March 2024, the US Department of the Treasury's OFAC imposed sanctions on the Intellexa Consortium and named individuals, including founder Tal Dilian, describing the consortium as a marketing label enabling targeted and mass surveillance. Legal consequences have also reached individuals connected to the ecosystem in Europe. These measures reflect a wider policy shift toward treating commercial spyware proliferation as a national-security and human-rights problem, though researchers note that public exposure alone has done little to stop the market.
How to defend against Predator spyware
Defending against high-end mobile spyware is difficult, but exposure can be meaningfully reduced, especially for the high-risk individuals most likely to be targeted.
- Keep devices fully updated. Because Predator relies on exploit chains, promptly installing OS and browser security updates closes the vulnerabilities it depends on.
- Reboot regularly and use hardened modes. Rebooting can disrupt some implants, and platform features such as Apple's Lockdown Mode are designed specifically to reduce the attack surface for targeted spyware.
- Treat unsolicited links with suspicion. Since one-click delivery depends on the target clicking a link over email, SMS, or messaging apps, high-risk users should avoid unexpected links and verify unusual messages out of band.
- Deploy mobile threat defense for organizations. Enterprises with at-risk staff should use mobile device management (MDM) and mobile threat defense (MTD) tooling, and monitor for the indicators of compromise that researchers publish, which are often malicious domains.
- Support at-risk users. Journalists, activists, and officials should have access to specialist help such as device checkups from digital-rights organizations, since they are the population Predator actually targets.
Predator spyware vs "Predator the Thief"
A common point of confusion is worth clearing up directly. Predator spyware, the subject of this page, is the Intellexa/Cytrox mobile surveillance product, and the terms "Predator spyware" and "Predator malware" are used interchangeably for it. It is entirely separate from "Predator the Thief," a Windows infostealer sold on Russian-language cybercrime forums since around 2018 to steal browser credentials, cryptocurrency data, and similar information. The two share only a name: different developers, different platforms, different purposes. If you are researching credential theft on Windows, that is Predator the Thief. If you are researching government mobile surveillance, that is Predator by Intellexa.
Expert insight: Commercial spyware is a threat-intelligence problem
Mercenary spyware like Predator sits at an awkward point for most security programs. It is engineered to evade antivirus, it often exploits zero-days, and it targets a small number of specific individuals rather than spreading widely, so conventional endpoint tooling rarely catches it, and most of the public indicators of compromise are malicious domains rather than file signatures. That makes commercial spyware primarily a threat-intelligence problem: knowing which infrastructure, domains, and delivery patterns a given vendor is using is often the most practical basis for detection.
This is where a CTI-led European vendor is relevant. Sekoia's in-house Threat Detection & Research team tracks commercial and mercenary spyware activity as part of the wider threat landscape, and that intelligence feeds the platform so that known Predator-related infrastructure and indicators can be flagged in context rather than missed as isolated traffic. For organizations that employ or protect high-risk individuals, combining that intelligence with mobile threat defense and disciplined update hygiene is a more realistic strategy than waiting for a signature to fire. As a European vendor with a data-sovereignty posture, Sekoia also aligns with the governance and human-rights concerns that surround the commercial spyware market.