SecurityWeek reports that Intellexa's Predator spyware features self-diagnostic capabilities allowing learning from previous failed attack attempts, highlighting the tool's sophistication.Embedded into Predator's CSWatcherSpawner architecture that provides precise diagnostics during failed deployments is a taxonomy of error codes, which offers details on the cause of aborted intrusions, according to a Jamf report. Numbering gaps in the error codes may signify the development of other codes for later versions of Predator or the removal of certain codes for a particular version of the spyware. Aside from avoiding execution in the U.S., Predator was also found to have a crash reporting-related anti-forensics routine that involved the removal of the target's crash log prior to examination."The presence of the is_corellium() stub shows they're watching our tools as closely as we're watching theirs," said Jamf researchers, who noted that the findings could be leveraged for reverse-engineering the spyware.
Privacy, Threat Intelligence
Predator spyware facilitates intelligence gathering from thwarted intrusions

Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


