Two Egyptians living in exile had their iPhones compromised in June 2021 using Predator spyware built by North Macedonian developer Cytrox
The Citizen Lab
Context & Ripple Effects
The report adds Cytrox's Predator to a record of targeted mobile surveillance against media-linked and exile communities: Citizen Lab had previously documented an iMessage zero-click chain used against Al Jazeera reporters, while Amnesty released a device-scanning toolkit in response to Pegasus infections. Predator's identification here matters because it ties a separate spyware vendor to iPhone targeting rather than treating NSO as the sole source of such risk.
First-order effects
The two Egyptian exiles face confirmed compromise of their iPhones, while Cytrox's Predator is publicly identified as the tool used against them.
Citizen Lab's attribution gives researchers and affected communities a concrete Predator case to distinguish from the earlier Pegasus-focused detection and reporting record.
The later reported infection of a Meta security-and-trust employee shows the documented Predator victim set extending beyond exiles, increasing the relevance of the case for companies whose staff handle sensitive information.
Third-order effects
If cases spanning exiles, journalists, and security personnel continue to accumulate, commercial spyware scrutiny will center on a wider supplier base than NSO alone, with Cytrox becoming a distinct target of investigation.
The pattern points toward mobile-device security as a cross-platform surveillance problem in which exploit attribution and forensic evidence become central to identifying vendor ecosystems.
The trend: Commercial spyware surveillance is broadening from a Pegasus-centered concern into a multi-vendor, cross-platform mobile-security challenge.
Two Spyware, One iPhone: A Khashoggi Murder Trial Witness Fears He Was Hacked By Rival Surveillance T... via @forbes https://www.forbes.com/... by @iblametom who has been on the Cytrox hunt for years....
MAJOR REPORT: we're exposing #Cytrox, a mercenary spyware company. Wild abuse case. Simultaneous *massive enforcement action* by @Meta against Cytrox + 6 other #surveillance4hire companies. Notifications to targets going out now... Get your🍿. THREAD https://citizenlab.ca/... http…
Exiled Egyptian opposition politician Ayman Nour is the latest dissident to have been hacked by the Israeli NSO Group's Pegasus spyware, which the Israeli government seems to have allowed one authoritarian government after another to use without limits. https://citizenlab.ca/... …
“The phone of Ayman Nour was simultaneously infected with both Cytrox's Predator and NSO Group's Pegasus spyware, operated by two different government clients.” Maybe spyware needs to look for competition and cleanup? https://citizenlab.ca/...
“For the first time ever, Armenia as a state has appeared in the list of countries that use spy programs domestically to infect and spy on people's phones.” —@Kornelij Investigation by @citizenlab follows earlier warnings by @RubenMuradyan Disturbing. https://citizenlab.ca/...
This is way bigger than Pegasus. Facebook and @citizenlab's reports expose the true scale of targeting and surveillance that activists, journalists, and everyday users face. https://www.washingtonpost.com/ ...
NSO Group is definitely on the ropes. However, our latest report should remind us that the problems around mercenary spyware go well beyond a single company. As one goes down, others will bounce up to make a buck. To solve abuse, we need governments to act.
We shared artifacts with Meta and Apple. Apple confirms investigating. Meta is taking enforcement action against Cytrox, removing 300 facebook pages and instagram accounts. See https://about.fb.com/...
Candiru, Cytrox, & NSO: all brought into the public eye by @citizenlab in just the last few of months. Our, the public's, understanding of the surveillance industry & its use against activists, journalists, & human rights defenders, is due in large part to them.
3/ @AymanNour was infected with #Cytrox's Predator via messages w/infection links. Clicking the links had resulted in the exploitation of his iPhone with an iOS zero day. Is Predator as sophisticated as NSO's Pegasus? No, strong B-Team vibes. Still, they rolled iOS 0-day. https:/…
1/ Today we shared a Threat Report on the surveillance-for-hire industry: a secretive global industry of entities that make hacking tools and spyware, sell them to anyone who will pay, and target victims indiscriminately. https://about.fb.com/...
There's a lot of interesting stuff in this new CL report. It's worth noting that devices that have been infected multiple times or that have been infected with more than one kind of spyware or even by more than one threat actor are not uncommon. https://twitter.com/...
Shout out to so the awesome research done by @citizenlab in their latest report A few years ago mobile device remote exploitation was rare, but in 2021 we have seen several incidents. These attacks are not going away unfortunately and capabilities are getting better. https://twit…
The phone of an exiled politician was simultaneously infected with both Cytrox's Predator and NSO Group's Pegasus spyware, operated by two different government clients🥴 https://citizenlab.ca/...
The @citizenlab report raises really serious concerns about the number of companies out there operating in the dark like #Cytrox that will only fill the market hole NSO Group leaves behind https://citizenlab.ca/...
One thing I hope we see in 2022 is more publications hiring dedicated beat reporters to write about NSO Group and these other cyber mercenaries. Surprisingly big, mostly unregulated industry with tens of thousands of victims https://twitter.com/...
@Meta @amnesty Our partners at @CitizenLab have published a detailed technical analysis of the Cytrox mobile spyware which they linked to an unlawful surveillance campaign targeting an Egyptian journalist and Ayman Nour, an Egyptian political activist https://citizenlab.ca/...