A human rights lawyer in Pakistan received an unexpected WhatsApp message last summer from someone posing as a journalist, complete with a realistic profile picture and a seemingly credible link to a European news site. The site was fake, the link was a lure, and according to Amnesty International’s Security Lab, it carried the signature of Predator – the spyware marketed by the Intellexa consortium, owned and run by Israelis abroad. As reporting by Haaretz and partners shows, the attempt was not isolated. Additional malicious links were sent to other Pakistanis, including politicians, indicating a broader effort to infiltrate devices in a country that has no diplomatic ties with Israel.
The revelations are part of “The Intellexa Leaks,” a cross-border investigation based on major internal leaks from the company. The materials, spanning 2018 to 2025, uncover Predator’s first documented use in Pakistan and expose how Intellexa, its founders and its affiliates continued to function despite U.S. sanctions imposed both on the company and on founder Tal Dilian in 2024. The investigation found that Predator infections were still active for multiple government clients, including Egypt, Saudi Arabia and Kazakhstan, while forensic indicators were also identified in Iraq – a country to which Israeli cyber firms are not licensed to export.
Predator is among the most invasive hacking tools available, capable of compromising both Apple and Google mobile operating systems. Once installed, it retrieves messages, accesses encrypted chats, listens to calls, and activates cameras and microphones. The leaked documents illustrate the company’s access to its clients’ systems in striking detail. A training video dated mid-2023 shows an Intellexa instructor remotely accessing the live espionage environment of a client codenamed “Eagle,” identified through forensic cross-confirmation as Kazakhstan. Using basic software like TeamViewer, the instructor scrolls through real-time infections and targeting data, an intrusion far deeper than the limited, support-only access spyware companies routinely claim.
Investigators say the video contradicts longstanding industry assertions that vendors cannot view client targeting. The footage instead shows a login screen with pre-filled credentials and a direct connection to an active surveillance platform. Experts from Amnesty argue that this level of access raises ethical and legal questions: whether government customers understood what the company could see, and how remote connections to such sensitive systems were approved or monitored.
Alongside the videos, newly leaked materials detail Intellexa’s clients through code names such as Dragon, Falcon, Flamingo, Lion, Phoenix and Tiger. Phoenix was previously linked to Libya; evidence points to additional clients in Angola, Egypt, Pakistan, Uzbekistan, Saudi Arabia and Tajikistan. Recorded Future, whose parallel report is published alongside the investigation, identified Predator infrastructure in northern Iraq and the Kurdish region. These findings underscore the widespread presence of Predator despite restrictions and attempts at regulatory oversight.
The leaks also confirm the existence of Aladdin, an “almost zero-click” infection method first revealed by Haaretz and Inside Story. Aladdin uses malicious advertising injected through commercial ad networks, enabling infections without fake links or user interaction — though it requires cooperation from a local internet service provider to supply IP-level targeting. Recorded Future found that companies linked to Intellexa in Dubai’s free-trade zones are already operationalizing the system, using ad-exchange ecosystems as a new and stealthy infection vector.
Corporate documents also illuminate Intellexa’s shift toward opaque corporate structures in the Gulf following U.S. sanctions. An analysis commissioned by Haaretz shows that shares once owned by Dilian in an Israeli entity were transferred to a company registered in an Abu Dhabi free-trade zone. Additional companies connected to Intellexa were identified across Dubai, forming part of a supply chain designed to move equipment, obscure ownership and evade scrutiny.
The investigation lands amid a major legal battle in Greece. There, Predator – also marketed under the name Helios – is at the center of a criminal case involving the hacking of journalist Thanasis Koukakis and other prominent figures. Dilian, who testified in Athens, denies any operational involvement. However, internal Intellexa code recovered by investigators matches samples previously found on Greek and Egyptian victims’ devices. While these files do not prove operational involvement, they underscore the company’s continued access to its products in multiple countries.
The leaked “Operational Security” manual, intended to hide Predator’s traces from investigators, has ironically become a key forensic reference point. Its technical identifiers match digital fingerprints found on targeted devices worldwide, reinforcing the findings of Amnesty and other research groups.
The broader context reflects a shifting regulatory environment. With the return of former U.S. President Donald Trump to the White House, several efforts to restrain the spyware industry have loosened, even as Intellexa remains on the Commerce Department’s blacklist. Other Israeli firms such as NSO and Candiru have moved under American ownership, while Paragon regained access to U.S. government contracts. Intellexa, not acquired by U.S. interests, appears instead to have adapted through offshore networks and increased operational secrecy.
Dilian, through his lawyers, issued a sweeping rejection of the investigation’s claims, calling them part of a coordinated campaign by political opponents, journalists and civil society groups. He says he has committed no crime and is pursuing legal action against individuals he accuses of defamation, including Koukakis. His statement argues that spyware vendors are unfairly targeted for the alleged misuses of sovereign clients, and compares the sale of offensive cyber tools to the export of conventional weapon systems.
Despite the denials, the leaked materials, technical evidence and new infections documented by multiple research teams point toward one conclusion echoed by Haaretz: Intellexa did not disappear under sanctions. It evolved, relocated and built new layers of obfuscation — remaining active, operational and entangled in some of the most sensitive digital espionage operations across the world.

