/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Two Egyptians living in exile had their iPhones compromised in June 2021 using Predator spyware built by North Macedonian developer Cytrox

Key Findings  — Two Egyptians—exiled politician Ayman Nour and the host of a popular news program (who wishes to remain anonymous) …

The Citizen Lab

Context & Ripple Effects

The targeting of Ayman Nour and another Egyptian media figure ties Cytrox's Predator to surveillance of people living outside Egypt, rather than an isolated device-security incident. Later coverage broadens that arc: Google described three Predator campaigns exploiting Android vulnerabilities, while reporting also linked Predator to the phone of a Meta security-and-trust employee working in Greece.

The case matters because it puts a named commercial spyware developer at the center of cross-border targeting of politically exposed individuals. It also sits alongside efforts to make mobile compromise detectable, including Amnesty's device-scanning toolkit for Pegasus evidence.

First-order effects

  • Ayman Nour and the unnamed broadcaster faced loss of confidentiality on compromised iPhones, exposing communications and contacts to the Predator operator.
  • Cytrox's Predator became directly associated with targeting Egyptian exiles, increasing scrutiny of the developer and the firms distributing comparable surveillance tools.

Second-order effects

  • Apple and other mobile-platform security teams face pressure to investigate and close the exploit paths used by commercial spyware; Google's later documentation of Predator Android campaigns indicates the exposure was not confined to one handset ecosystem.
  • Exiled political figures, journalists, and rights groups gain a concrete reason to use compromise-detection practices, expanding demand for independent forensic support rather than relying solely on platform notifications.

Third-order effects

  • Repeated Predator cases across targets and mobile platforms point toward commercial spyware operating as a cross-border surveillance supply chain, making vendor attribution as consequential as identifying the immediate operator.
  • If researchers and platform vendors continue publishing technical evidence, the market's ability to operate quietly weakens, raising the likelihood of more sustained scrutiny of spyware developers and their customers.

The trend: Commercial spyware is becoming a multi-platform, cross-border surveillance risk whose exposure increasingly depends on independent forensic research and platform threat investigations.

Discussion

  • @jsrailton John Scott-Railton on x
    MAJOR REPORT: we're exposing #Cytrox, a mercenary spyware company. Wild abuse case. Simultaneous *massive enforcement action* by @Meta against Cytrox + 6 other #surveillance4hire companies. Notifications to targets going out now... Get your🍿. THREAD https://citizenlab.ca/... http…
  • @citizenlab @citizenlab on x
    NEW REPORT Pegasus vs. Predator: Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware https://citizenlab.ca/...
  • @rondeibert Profdeibert on x
    Two Spyware, One iPhone: A Khashoggi Murder Trial Witness Fears He Was Hacked By Rival Surveillance T... via @forbes https://www.forbes.com/... by @iblametom who has been on the Cytrox hunt for years....
  • @kenroth Kenneth Roth on x
    Exiled Egyptian opposition politician Ayman Nour is the latest dissident to have been hacked by the Israeli NSO Group's Pegasus spyware, which the Israeli government seems to have allowed one authoritarian government after another to use without limits. https://citizenlab.ca/... …
  • @thegrugq Thaddeus E. Grugq on x
    “The phone of Ayman Nour was simultaneously infected with both Cytrox's Predator and NSO Group's Pegasus spyware, operated by two different government clients.” Maybe spyware needs to look for competition and cleanup? https://citizenlab.ca/...
  • @lindseyod123 Lindsey O'Donnell Welch on x
    The phone of an exiled politician was simultaneously infected with both Cytrox's Predator and NSO Group's Pegasus spyware, operated by two different government clients🥴 https://citizenlab.ca/...
  • @evacide Eva on x
    There's a lot of interesting stuff in this new CL report. It's worth noting that devices that have been infected multiple times or that have been infected with more than one kind of spyware or even by more than one threat actor are not uncommon. https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    3/ @AymanNour was infected with #Cytrox's Predator via messages w/infection links. Clicking the links had resulted in the exploitation of his iPhone with an iOS zero day. Is Predator as sophisticated as NSO's Pegasus? No, strong B-Team vibes. Still, they rolled iOS 0-day. https:/…
  • @ngleicher Nathaniel Gleicher on x
    1/ Today we shared a Threat Report on the surveillance-for-hire industry: a secretive global industry of entities that make hacking tools and spyware, sell them to anyone who will pay, and target victims indiscriminately. https://about.fb.com/...
  • @ngleicher Nathaniel Gleicher on x
    Very deep dive on what surveillance-for-hire looks like today, and what society is/can/should do to contain it! https://twitter.com/...
  • @caseynewton Casey Newton on x
    One possible takeaway from the size of this industry is that Apple's bug bounty program isn't really working. If you have thoughts on that DM me!
  • @razhael Raphael Satter on x
    Thread by @jsrailton here on the previously obscure Cytrox ↘️ https://twitter.com/...
  • @tonyajoriley Tonya Riley on x
    The @citizenlab report raises really serious concerns about the number of companies out there operating in the dark like #Cytrox that will only fill the market hole NSO Group leaves behind https://citizenlab.ca/...
  • @laughing_mantis Greg Linares on x
    Shout out to so the awesome research done by @citizenlab in their latest report A few years ago mobile device remote exploitation was rare, but in 2021 we have seen several incidents. These attacks are not going away unfortunately and capabilities are getting better. https://twit…
  • @rondeibert Profdeibert on x
    NSO Group is definitely on the ropes. However, our latest report should remind us that the problems around mercenary spyware go well beyond a single company. As one goes down, others will bounce up to make a buck. To solve abuse, we need governments to act.
  • @maddiestone Maddie Stone on x
    Candiru, Cytrox, & NSO: all brought into the public eye by @citizenlab in just the last few of months. Our, the public's, understanding of the surveillance industry & its use against activists, journalists, & human rights defenders, is due in large part to them.
  • @caseynewton Casey Newton on x
    One thing I hope we see in 2022 is more publications hiring dedicated beat reporters to write about NSO Group and these other cyber mercenaries. Surprisingly big, mostly unregulated industry with tens of thousands of victims https://twitter.com/...
  • @accessnow @accessnow on x
    This is way bigger than Pegasus. Facebook and @citizenlab's reports expose the true scale of targeting and surveillance that activists, journalists, and everyday users face. https://www.washingtonpost.com/ ...
  • @rondeibert Profdeibert on x
    We shared artifacts with Meta and Apple. Apple confirms investigating. Meta is taking enforcement action against Cytrox, removing 300 facebook pages and instagram accounts. See https://about.fb.com/...
  • @alitahmizian Alison Tahmizian Meuse on x
    “For the first time ever, Armenia as a state has appeared in the list of countries that use spy programs domestically to infect and spy on people's phones.” —@Kornelij Investigation by @citizenlab follows earlier warnings by @RubenMuradyan Disturbing. https://citizenlab.ca/...
  • @amnestytech @amnestytech on x
    @Meta @amnesty Our partners at @CitizenLab have published a detailed technical analysis of the Cytrox mobile spyware which they linked to an unlawful surveillance campaign targeting an Egyptian journalist and Ayman Nour, an Egyptian political activist https://citizenlab.ca/...
  • @runasand Runa Sandvik on x
    NSO is not the only spyware firm out there. New research by @citizenlab details Predator by Cytrox. https://citizenlab.ca/...
  • @cpjtechnology @cpjtechnology on x
    Another journalist targeted with Pegasus spyware... https://twitter.com/...
  • @ngleicher Nathaniel Gleicher on x
    4/ We've mapped each of these companies across the Surveillance Attack Chain: 3 stages (recon -> engagement -> exploit) that these companies follow as they target people for spying around the world. https://twitter.com/...
  • @evacide Eva on x
    Just in case you're looking through the names of surveillance-for-hire companies Meta is taking action against and Belltrox sounds familiar, they were behind the Phish for the Future campaign @cooperq and I wrote about: https://www.eff.org/...
  • @marietjeschaake Marietje Schaake on x
    More great work by @citizenlab on the spyware market (not just NSO) this time targeting @AymanNour ↘️ https://twitter.com/...
  • @dashdecosta Leon Dash on x
    “The surveillance industry is much bigger than just one company. The targeting we see is indiscriminate. They're targeting journalists. They're targeting politicians. They're targeting human rights defenders. They're also targeting ordinary citizens.” https://www.washingtonpost.c…
  • @rj_gallagher Ryan Gallagher on x
    Meta on Thursday named four Israeli firms as having been involved in providing the “surveillance-for-hire” services — Cobwebs Technologies, Cognyte, Black Cube & Bluehawk CI — in addition to India's BellTrox, North Macedonia's Cytrox & an unknown entity in China.
  • @migueldeicaza @migueldeicaza on x
    Facebook is delivering our Xmas present: https://twitter.com/...
  • @davidakaye David Kaye on x
    key explainer 🧵 from one of the leading #spyware experts @jsrailton concerning major new @citizenlab report & @Meta enforcement https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    Gleicher is a co-author on the big Facebook report. Here he helps map out what they're calling the Surveillance Attack Chain. Very useful illustration of how the industry is bigger than the small slice the public has focused in on. https://twitter.com/...
  • @arawnsley Adam Rawnsley on x
    Big news: Meta ID'ed and took action against 7 mercenary surveillance companies. One of them, the Israeli-Macedonian firm Cytrox, hacked the iPhones of Egyptian targets, including one already infected with NSO Group's Pegasus malware. @citizenlab https://www.thedailybeast.com/ ..…
  • @bing_chris Chris Bing on x
    Facebook exposes mercenary spy firms that targeted 50,000 people https://www.reuters.com/...
  • @evacide Eva on x
    What do I think Meta should do next about the surveillance-for-hire industry? I think they should sue their pants off.
  • @w7voa Steve Herman on x
    About 50,000 @Facebook users being alerted they may have been hacking targets by surveillance companies working for government agencies or private clients. https://about.fb.com/...
  • @ngleicher Nathaniel Gleicher on x
    3/ We're also alerting about 50,000 people in 100+ countries that we believe were targeted by these firms.
  • @tomgara Tom Gara on x
    “we took action against seven different surveillance-for-hire entities. They provided services across all three phases of the surveillance chain to indiscriminately target people in over 100 countries” https://about.fb.com/...
  • @jsrailton John Scott-Railton on x
    4/ Cytrox has an EU footprint, & is part of Intellexa... which also brags of being regulated within the EU. Hello, regulators? Also, their CEO seems to think he's spyware's answer to Steve Jobs. They are about to have a horrid weekend for another reason: @meta's enforcement... ht…
  • @blackamazon @blackamazon on x
    This sucks and no they did not warn everyone https://twitter.com/...
  • @agreendcbike Antoine McGrath on x
    It's a relief to see heavyweights drawing the line on spyware. A rightly earned nod to Meta today Vulnerabilities need to be patched not exploited, if the ‘good guys’ use it so will the bad As always amazing research @citizenlab @billmarczak https://twitter.com/...
  • @carolafrediani Carola Frediani on x
    Meta disrupted 7 ‘surveillance-for-hire’ networks and alerted 50,000 users. These surveillance groups targeted, spied on and at times attempted to exploit users in 100 countries https://about.fb.com/...
  • @skirchy Stephanie Kirchgaessner on x
    One of Facebook's messages here is: great that everyone is hearing about NSO Group. They're not the only ones. https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    Citizen Lab has a new report out on the hacker-for-hire firm Cytrox: https://citizenlab.ca/... Cytrox is part of the Intellexa alliance of intelligence firms created explicitly to compete with industry giant NSO Group. I scooped that here a few years back: https://gizmodo.com/...
  • @jsrailton John Scott-Railton on x
    5/ Let's talk about @Meta's massive enforcement action today. Starting with #Cytrox. They are swinging hard: ✅sent a cease & desist letter ✅killed 100s of accounts ✅notified targets globally ✅are dropping 100s of Cytrox indicators But this is just the appetizer... https://twitter…
  • @davidakaye David Kaye on x
    big @meta report on threats from private #spyware industry, with this key point for USG & global policymakers: “NSO is only one piece of a much broader global cyber mercenary industry.” https://about.fb.com/...
  • @jsrailton John Scott-Railton on x
    13/ The @meta notifications are a big deal. How big? ~50k targets 100+ countries Hear that sound? That's #surveillance4hire customers' stomaches churning as they wonder this will come back on them. https://twitter.com/...
  • @davidagranovich David Agranovich on x
    1/ Today we released our research into the Surveillance-for-Hire industry. It includes 7 enforcements against surveillance entities from India, Israel, China, and North Macedonia and recommendations for holding this industry accountable. 🧵: https://about.fb.com/...
  • @jsrailton John Scott-Railton on x
    15/ Slowing the harm from #surveillance4hire requires hitting hard, but systematically. It's great to see big platforms like @meta rock these mercenary spooks' world. Next key ingredient? Serious regulatory scrutiny, lawmaking & oversight are urgently needed. https://twitter.com/…
  • @joyce_karam Joyce Karam on x
    One surveillance co., Cytrox, busted by Facebook is based in N Macedonia was hired by 10 Gov.: 1- Egypt 2- Armenia 3- Greece 4- Saudi Arabia 5- Oman 6- Colombia 7- Ivory Coast 8- Vietnam 9- The Philippines 10- Germany https://www.washingtonpost.com/ ...
  • @anthony Anthony DeRosa on x
    Here is the Facebook (Meta) statement on the action: https://about.fb.com/...
  • @jckichen @jckichen on x
    For every firm written about or technically compromised, there will be many more operating amidst the noise of criminal and state actors, likely more and more indistinguishable based on either targeting or technology. https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    The ban aims to stop the groups from using Facebook, Instagram, etc. to send malicious links to victims. Meta says it's notified around 50,000 people that they were targets of the seven groups. https://techcrunch.com/...
  • @iblametom Thomas Brewster on x
    Another one of the companies named and shamed by Facebook, as well as being thrown off its apps, is Cobwebs Technologies. It has contracts with the DHS and IRS. I asked Facebook whether it was worried about upsetting US investigations: https://www.forbes.com/...
  • @anthony Anthony DeRosa on x
    Spies for hire are secretly targeting journalists, human rights activists and political dissidents on behalf of corporations and governments to an extent not previously understood, Facebook's parent company says in a new report https://www.nbcnews.com/...
  • @iblametom Thomas Brewster on x
    The second was Cytrox, a mysterious company once acquired by surveillance “alliance” Intellexa. The chief of that company once showed off a van that could hack into WhatsApp messages from hundreds of meters away. https://www.forbes.com/...
  • @washingtonpost @washingtonpost on x
    Facebook is warning 50,000 users they may have been victims of private spyware https://www.washingtonpost.com/ ...
  • @zackwhittaker Zack Whittaker on x
    New: Meta has banned 7 surveillance-for-hire outfits from its platforms, including Cytrox, a spyware maker that Citizen Lab says hacked into the iPhones of a politician and a journalist. https://techcrunch.com/...