Back Mezha Intellexa's Predator Spyware Used to Hack Angolan Journalist's Phone - Межа
According to Amnesty International, an Intellexa government client hacked the phone of a well-known Angolan journalist using Predator spyware, signaling a rising practice of using powerful software against civil society actors.
Amnesty published a new report detailing several hacking attempts against the local journalist and freedom of the press activist Teixeira Candido. In 2024 he was sent a series of malicious links via WhatsApp, and after clicking them his iPhone was hacked.
According to researchers, Predator was used to attack Candido, and a trend was highlighted: government clients of private surveillance vendors are increasingly applying spyware to pressure journalists, politicians, and other citizens, including regime critics.
Amnesty’s study also cites cases of Predator use in Egypt, Greece, and Vietnam, where the government allegedly targeted U.S. officials by sending spyware through a link on the social network X.
Intellexa is considered one of the most controversial spyware companies in recent years. The company operates under various jurisdictions to evade export controls, and, according to U.S. government officials, uses an opaque web of corporate structures.
In 2024, the U.S. administration imposed sanctions on Intellexa, its founder Tal Dilian, and business partner Sara Alexandra Faisal Hamou. Earlier this year the Department of the Treasury lifted sanctions on three other company executives, prompting questions from senators the stance of the U.S. administration.
Dilian did not respond to a request for .
Amnesty explains that the link to Intellexa was established through forensic analysis on Candido’s phone: researchers note the use of infection servers, previously linked to the spyware company’s infrastructure.
According to Amnesty, a few hours after clicking the link that led to the breach, Candido rebooted the device, effectively erasing the spyware from the phone’s hardware. The report also notes that using an outdated iOS made it difficult to determine the exact path of the intrusion.
Researchers found that Predator remained hidden, masquerading as legitimate iOS system processes to avoid detection.
Amnesty believes that Candido may be just one of many targets in Angola, based on findings several domains linked to the spyware producer used in the country.
“The first domains linked to Angola were deployed as early as March 2023, indicating the start of testing or deployment of Predator in the country.”
«Currently it is not possible to definitively identify the client of Predator spyware in this country,» Amnesty International says.
“Currently it is not possible to definitively identify the client of Predator spyware in this country,”
Last year, Amnesty and several media organizations published internal documents showing the possibility of remote access by Intellexa employees to client systems, giving the spyware vendor access to government surveillance operations.
These data, like the new Amnesty report, show that despite controversy and sanctions, Intellexa has continued to operate in recent years.
“We now see confirmed abuses in Angola, Egypt, Pakistan, Greece and beyond – and for every case we uncover, many other abuses undoubtedly remain hidden.”
Lorenzo Franceschi-Bicchierai, senior writer at TechCrunch, is responsible for pieces on hacking, cybersecurity, and privacy. He can be reached via email at [email protected] , encrypted messages via Signal at +1 917 257 1382, or via Keybase/Telegram @lorenzofb.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
