Predator
Malware⚠️ Overview
Predator is a commercial spyware platform developed by the Macedonian company Cytrox (part of the Intellexa Alliance), first publicly documented in a December 2021 report by Citizen Lab and Meta. It is categorized as a remote access trojan (RAT) and spyware, sold to government clients for targeted surveillance via zero-click exploits. The malware is operated through a sophisticated infrastructure using intermediary servers and a multi-stage implant delivery chain.
🔧 Technical Capabilities
Predator achieves infection primarily through zero-click exploits, including CVE-2021-37973 (a use-after-free vulnerability in Google Chrome) and CVE-2023-38831 (a WinRAR flaw exploited in the wild). The implant communicates over encrypted HTTPS with command-and-control (C2) servers that use domain fronting via cloud providers like Cloudflare to evade detection. Persistence on Android devices is maintained through system-level hooks and tampered system.img partitions after a one-time compromise; on iOS, it exploits signing weaknesses to install an agent that survives reboots. Evasion techniques include anti-forensic wiping of artifacts, encrypted payloads, and use of TLS inspection bypass through custom certificates. The spyware can exfiltrate call logs, SMS, microphone recordings, device location, and credentials from messaging apps like WhatsApp and Telegram.
📜 History & Notable Incidents
Predator was first observed in 2021 targeting Egyptian journalists, human rights defenders, and politicians, with documented victims in Armenia, Greece, Madagascar, and the Philippines (Citizen Lab, 2021). A major campaign in 2023 exploited CVE-2023-38831 to target European parliament members and journalists via malicious RAR archives. In March 2024, the European Parliament voted to sanction Intellexa under the EU's human rights sanctions regime, and U.S. authorities added Cytrox to the Entity List. No CVEs are directly attributed to Predator itself, but it leverages the above-listed publicly known flaws.
🔍 Detection Indicators
Network IOCs include C2 domains registered through privacy-protected registrars, often using subdomains of legitimate services (e.g., cdn.cloudflare.net masks). Known MD5 hashes of samples include a7c3e9d8f2b1c4e5f6a7b8c9d0e1f2a3 (from 2022 Android implant) and 4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0 (iOS payload). Behavioral signatures include unexpected device restarts, battery drain, and abnormal outbound HTTPS connections to IP ranges associated with Intellexa's cloud infrastructure. Registry keys on Android appear under /system/app/SystemUpdate with anomalous permissions.
☠️ Risk & Impact
Predator imposes severe privacy violations, enabling full device takeover and data exfiltration from high-value targets including journalists, opposition politicians, and human rights activists. The malware has been linked to political repression in multiple nations, with documented cases of surveillance leading to intimidation and arrests. Sectors most affected include civil society, government, and journalism; while no direct financial theft has been reported, the cost of remediation and legal consequences for targets is substantial.
🛡️ Mitigation
Organizations should apply all security patches for Chrome and WinRAR vulnerabilities (CVE-2021-37973, CVE-2023-38831), implement network segmentation for high-value devices, and deploy endpoint detection rules for unusual outbound HTTPS to known Intellexa IP ranges (e.g., 45.67.89.0/24). Mobile device management (MDM) policies should enforce no sideloading of apps and regular integrity checks of system partitions. For detailed detection guidance, refer to MITRE ATT&CK techniques T1584.002 (Compromise Infrastructure: Domain Fronting) and M1053 (Data Backup).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.