Privacy, Threat Intelligence

Predator spyware facilitates intelligence gathering from thwarted intrusions

SecurityWeek reports that Intellexa's Predator spyware features self-diagnostic capabilities allowing learning from previous failed attack attempts, highlighting the tool's sophistication.

Embedded into Predator's CSWatcherSpawner architecture that provides precise diagnostics during failed deployments is a taxonomy of error codes, which offers details on the cause of aborted intrusions, according to a Jamf report. Numbering gaps in the error codes may signify the development of other codes for later versions of Predator or the removal of certain codes for a particular version of the spyware. Aside from avoiding execution in the U.S., Predator was also found to have a crash reporting-related anti-forensics routine that involved the removal of the target's crash log prior to examination.

"The presence of the is_corellium() stub shows they're watching our tools as closely as we're watching theirs," said Jamf researchers, who noted that the findings could be leveraged for reverse-engineering the spyware.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds