2.6 KiB
2.6 KiB
Predator Spyware Indicators of Compromise
This repository contains network and device indicators of compromised (IoCs) related to the IOS and Android Predator spyware tools developed by the cyber-surveillance company Intellexa (formerly Cytrox). These indicators were extracted from multiple reports including:
- Threat Report on the Surveillance-for-Hire Industry by Meta
- "Pegasus vs. Predator - Dissident’s Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware" report by the Citizen Lab
- "Predator in the wires - Ahmed Eltantawy Targeted with Predator Spyware After Announcing Presidential Ambitions" report by the Citizen Lab
- Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware by Cisco Talos
- Predatorgate: Τι έγραφαν τα SMS-παγίδα που έλαβαν επιχειρηματίες, υπουργοί και δημοσιογράφοι by Inside Story
- Active Lycantrox infrastructure illumination by Sekoia
- Predator Spyware Operators Rebuild Multi-Tier Infrastructure to Target Mobile Devices by Recorded Future
- The Predator spyware ecosystem is not dead by Sekoia
- Trust Broken at the Core by iVerify
- Additional indicators of compromise were identified by the Amnesty Tech Security Lab as part of an independent investigation.
The STIX2 file can be used with the Mobile Verification Toolkit to look for potential signs of compromise on Android phones and iPhones.
It includes the following files:
config_profiles.txt: UUID of suspicious configuration profiles dropped by the Predator spywarepredator.stix2: STIX2 file containing all indicatorsdomains.txt: list of Predator domainsfile_paths.txt: file paths for Predator payloads on disk in Android and iOS.