US Cracks Down on Predatory Spyware Firm

12399903899?profile=RESIZE_400xThe US Department of Treasury's Office of Foreign Assets Control (OFAC) sanctioned two individuals and five entities associated with the Intellexa Alliance for their role in "developing, operating, and distributing" commercial spyware designed to target government officials, journalists, and policy experts in the country.  "The proliferation of commercial spyware poses distinct and growing security risks to the United States and has been misused by foreign actors to enable human rights abuses and the targeting of dissidents around the world for repression and reprisal," the agency said.

See:  https://redskyalliance.org/xindustry/spyware-can-ruin-your-day

"The Intellexa Consortium, which has a global customer base, has enabled the proliferation of commercial spyware and surveillance technologies around the world, including to authoritarian regimes."   The Intellexa Alliance is a consortium of several companies, including Cytrox, linked to a mercenary spyware solution called Predator. In July 2023, the US government added Cytrox and Intellexa and their corporate holdings in Hungary, Greece, and Ireland to the Entity List.[1]

Like NSO Group's Pegasus, Predator can infiltrate Android and iOS devices using zero-click attacks that require no user interaction.  Once installed, the spyware makes it possible for the operators to harvest sensitive data and surveil targets of interest.  OFAC said unspecified foreign actors had deployed Predator against U.S. government officials, journalists, and policy experts.  "In the event of a successful Predator infection, the spyware's operators can access and retrieve sensitive information, including contacts, call logs, messaging information, microphone recordings, and media from the device," the Treasury Department said.

The sanctions designations apply to the following individuals and entities:

  • Tal Jonathan Dilian (Dilian), the founder of the Intellexa Consortium
  • Sara Aleksandra Fayssal Hamou (Hamou), a corporate off-shoring specialist who has provided managerial services to the Intellexa Consortium
  • Intellexa S.A., a Greece-based software development company
  • Intellexa Limited, an Ireland-based company
  • Cytrox AD, a North Macedonia-based company that's responsible for the development of Predator
  • Cytrox Holdings Zartkoruen Mukodo Reszvenytarsasag (Cytrox Holdings ZRT), a Hungary-based entity
  • Thalestris Limited, an Ireland-based entity that holds distribution rights to the Predator spyware

The following firms, Intellexa S.A., Intellexa Limited, Cytrox AD, and Cytrox Holdings ZRT, were added to the economic blocklist in 2023.

New revelations about Predator's multi-tiered delivery infrastructure from Recorded Future and Sekoia prompted the operators to shut down their servers.  The sanctions targeting the makers of Predator also arrived after the US government unveiled a new policy last month that will allow it to impose visa restrictions on foreign individuals involved in the misuse of commercial spyware.

Citizen Lab security researcher John Scott-Railton described the OFAC designations as a huge deal, stating they mark the "first time they're used against a mercenary spyware company."

"The United States remains focused on establishing clear guardrails for the responsible development and use of these technologies while also ensuring the protection of human rights and civil liberties of individuals around the world," said Under Secretary of the Treasury for Terrorism and Financial Intelligence Brian E. Nelson.

 

This article is presented at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.     For questions, comments, or assistance, please get in touch with the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

 

  • Reporting: https://www. redskyalliance. org/
  • Website: https://www. redskyalliance. com/
  • LinkedIn: https://www. LinkedIn. com/company/64265941 

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/5504229295967742989

 

[1] https://thehackernews.com/2024/03/us-cracks-down-on-predatory-spyware.html

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!