Julian-Ferdinand Vögele's Avatar

Julian-Ferdinand Vögele

@julianferdinand.bsky.social

Threat Research @ Recorded Future. Previously @ Security Research Labs. He/Him. 🏳️‍🌈

1,262 Followers  |  187 Following  |  188 Posts  |  Joined: 18.10.2023  |  2.4366

Latest posts by julianferdinand.bsky.social on Bluesky

Preview
Intellexa remotely accessed Predator spyware customer systems, investigation finds It was one of a trio of reports about the spyware vendor over the course of a day, with additional evidence about further infections among the findings.

It was one of a trio of reports about the spyware vendor over the course of a day, with additional evidence about further infections among the findings. via @timstarks.bsky.social cyberscoop.com/intellexa-re...

04.12.2025 22:31 — 👍 3    🔁 4    💬 0    📌 0
Preview
Intellexa’s Prolific Zero-Day Exploits Continue | Google Cloud Blog Commercial surveillance vendor Intellexa continues to thrive and exploit mobile zero-day vulnerabilities.

Interesting artefact in the uploaded JSKit code used by Intellexa from Google's Threat Intelligence Group.

"//TODO: va bene solo per ios 15 perchè l'exploit è uguale per tutte le version 15.0.x infatti se inferiore a 15.1 restituisce sempre 15.0" - some italian....

cloud.google.com/blog/topics/...

04.12.2025 21:20 — 👍 4    🔁 4    💬 0    📌 1
Post image Post image Post image Post image

Intellexa Predator cyber tool (spyware hacking user devices) operates across multiple countries, recent targets identified in Pakistan, Kazakhstan, Angola, Egypt, Uzbekistan, Saudi Arabia, and Tajikistan. Among the users are at least 25 countries including Germany, Austria, Switzerland, Qatar, Congo

04.12.2025 15:34 — 👍 8    🔁 3    💬 1    📌 0
Preview
Predator spyware uses new infection vector for zero-click attacks The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.

The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed "Aladdin" that compromised specific targets when simply viewing a malicious advertisement.

04.12.2025 15:48 — 👍 6    🔁 4    💬 0    📌 0
Preview
Researchers find Predator spyware is being used in several countries, including Iraq Researchers also found indicators “likely associated” with the use of Predator spyware by an entity tied to Pakistan.

Insikt Group researchers found new evidence of Predator's continued deployment in Iraq and Pakistan. New shell companies and other interconnected firms also discovered and suggest "expanding network footprint."

therecord.media/intellexa-pr...

04.12.2025 17:08 — 👍 3    🔁 3    💬 0    📌 0

Toadya our research partners at Google TAG and Recorded Future (@julianferdinand.bsky.social)
) have published their own deep investigations into Intellexa

bsky.app/profile/juli...

04.12.2025 14:38 — 👍 2    🔁 1    💬 1    📌 0
Post image

🔥 The #IntellexaLeaks
⚠ Νέα διεθνής έρευνα του @insidestory.gr σε συνεργασία με την @haaretzcom.bsky.social, WAV Research Collective και την τεχνική συνδρομή του Εργαστηρίου Ασφαλείας της @amnesty.org προχωρά σήμερα σε σημαντικές αποκαλύψεις: insidestory.gr/article/inte...

04.12.2025 13:24 — 👍 5    🔁 5    💬 1    📌 1

Incredible work from our Insikt Group and @julianferdinand.bsky.social

04.12.2025 12:30 — 👍 6    🔁 2    💬 0    📌 0
Post image

🚨 - New report by Haaretz, Inside Story, Inside-IT and Amnesty International release the Intellexa Leaks. Which exposes Intellexa support staff had access through Teamviewer to customer deployments and confirms found IOC's in the past by civil society. 🧵👇

04.12.2025 11:37 — 👍 9    🔁 16    💬 1    📌 3

5️⃣ Εκτός από το Security Lab της Διεθνούς Αμνηστίας, σήμερα δημοσιεύουν επίσης ξεχωριστές εκθέσεις η Google Threat Intelligence Group και η εταιρεία κυβερνοασφάλειας Recorded Future οι οποίες επιβεβαιώνουν τα ευρήματα της έρευνάς μας.

04.12.2025 06:33 — 👍 1    🔁 1    💬 1    📌 0

1️⃣ The Intellexa Leaks: Νέα διεθνής έρευνα του #insidestory_gr και της @etriantafillou.bsky.social σε συνεργασία με την ισραηλινή εφημερίδα @haaretzcom.bsky.social, την ομάδα WAV Research Collective στην Ελβετία και την τεχνική συνδρομή του Εργαστηρίου Ασφαλείας της Διεθνούς Αμνηστίας.

04.12.2025 06:33 — 👍 5    🔁 6    💬 1    📌 1

Thank you! :)

04.12.2025 06:49 — 👍 1    🔁 0    💬 0    📌 0
Preview
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations...

And check out the companion blog post by @amnestyuk.bsky.social tech with a detailed peek into Intellexa's setup based on leaked materials 👀

Giveaway: Intellexa can observe all of what their gov clients are doing with their hacking tech and more securitylab.amnesty.org/latest/2025/...

04.12.2025 05:03 — 👍 7    🔁 3    💬 1    📌 0

Thank you! :)

04.12.2025 05:06 — 👍 1    🔁 0    💬 0    📌 0

Great work showing yet more
mercenary spyware abuses, this time in Iraq and Pakistan involving shady Intellexa and its Predator spyware 👇

04.12.2025 05:00 — 👍 12    🔁 6    💬 1    📌 0
Preview
Intellexa’s Global Corporate Web

A new report by Insikt Group @julianferdinand.bsky.social identifies several individuals & entities linked to Intellexa & its broader network of associated companies, as well as newly identified activity clusters in 🇮🇶Iraq & indications of activity in 🇵🇰Pakistan.
www.recordedfuture.com/research/int...

04.12.2025 04:51 — 👍 3    🔁 1    💬 0    📌 0
Preview
Intellexa’s Global Corporate Web

12/ Check out our full report here: www.recordedfuture.com/research/int...

04.12.2025 04:17 — 👍 4    🔁 0    💬 0    📌 0
Preview
Former Intellexa Employee Testifies to Secret Demonstrations of Spyware to Foreign Intelligence Services - Dnews What emerged in court is that this structure allowed Intellexa to continue operating despite U.S. sanctions. The trial over Greece’s Predator spyware scandal resumed on Tuesday at the Athens Misdemean...

11/ Our report, alongside Amnesty International’s and Google’s, lands as Intellexa’s trial over Greece’s Predator spyware scandal resumed this week at the Athens Misdemeanors Court: www.dnews.gr/eidhseis/new...

04.12.2025 04:17 — 👍 10    🔁 0    💬 2    📌 0
Preview
Intellexa’s Prolific Zero-Day Exploits Continue | Google Cloud Blog Commercial surveillance vendor Intellexa continues to thrive and exploit mobile zero-day vulnerabilities.

10/ This is consistent with Google’s findings, which indicate continuing activity in these and other countries. They also reported on Intellexa today, noting its extensive use of zero-days (accounting for 16 of the 70 discovered/documented by Google since 2021): cloud.google.com/blog/topics/...

04.12.2025 04:17 — 👍 7    🔁 0    💬 1    📌 0

9/ Using Recorded Future’s Network Intelligence, we further mapped Predator activity timelines across multiple clusters. Several, including in Mongolia, Saudi Arabia, and Kazakhstan, remain active today, indicating that sanctions and previous reporting have had only partial impact.

04.12.2025 04:17 — 👍 7    🔁 0    💬 1    📌 0
Post image

8/ Among Amnesty’s most concerning revelations: at the time the leaked training videos were recorded, Intellexa retained the capability to remotely access Predator customer systems, including those located on-premises within government facilities.

04.12.2025 04:17 — 👍 8    🔁 1    💬 1    📌 0
To Catch a Predator: Leak exposes the internal operations of Intellexa’s mercenary spyware - Amnesty International Security Lab Drawing on leaked internal company documents, sales and marketing material, as well as training videos, the “Intellexa Leaks” investigation gives a never-before-seen glimpse of the internal operations...

7/ These findings surface as @amnesty.org publishes new insights into “Aladdin,” based on internal corporate leaks such as training videos and marketing documents, released publicly for the first time today: securitylab.amnesty.org/latest/2025/...

04.12.2025 04:17 — 👍 7    🔁 0    💬 1    📌 0
Post image

6/ Two entities in the advertising sector (also linked to the Czech cluster) may be connected to the “Aladdin” ad-based infection vector, originally revealed by Haaretz and previously tied to the Czech cluster via a leaked 2022 invoice.

04.12.2025 04:17 — 👍 7    🔁 0    💬 1    📌 0
Post image

5/ We also identified additional entities in Kazakhstan (OOO Seven Hills) and the Philippines (ComWorks) involved in importing Intellexa products, highlighting Intellexa’s continued global corporate expansion.

04.12.2025 04:17 — 👍 7    🔁 0    💬 1    📌 0
Post image

4/ In at least one instance, a delivery very likely went directly to an end user, offering a rare look into how Intellexa tools reach their final destinations. The timing aligns closely with our prior reporting on the Botswana cluster.

04.12.2025 04:17 — 👍 8    🔁 0    💬 1    📌 0
Post image

3/ By examining corporate records, infrastructure, and export/import data, we identified an entity (PULSE FZCO) tied to the previously reported Czech cluster that highly likely facilitated shipments of Intellexa products to clients.

04.12.2025 04:17 — 👍 7    🔁 0    💬 1    📌 0

2/ This report is one of multiple investigations undertaken in coordination with @amnesty.org and Google, each of which also issued independent, complementary reports today.

04.12.2025 04:17 — 👍 9    🔁 0    💬 1    📌 0
Preview
Intellexa’s Global Corporate Web

1/ Today we release a new report exposing previously undisclosed entities connected to the wider #Intellexa ecosystem as well as newly identified activity clusters in Iraq and indications of activity in Pakistan: www.recordedfuture.com/research/int...

04.12.2025 04:17 — 👍 25    🔁 20    💬 2    📌 4
Preview
Former Intellexa Employee Testifies to Secret Demonstrations of Spyware to Foreign Intelligence Services - Dnews What emerged in court is that this structure allowed Intellexa to continue operating despite U.S. sanctions. The trial over Greece’s Predator spyware scandal resumed on Tuesday at the Athens Misdemean...

"What emerged in court - and what carries significant implications beyond Greece - is that this structure allowed Intellexa to continue operating despite 🇺🇸U.S. sanctions imposed on the company and its shareholders over the global deployment of Predator #spyware."

www.dnews.gr/eidhseis/new...

03.12.2025 07:14 — 👍 14    🔁 11    💬 1    📌 1
Preview
MuddyWater: Snakes by the riverbank MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook.

#ESETresearch discovered a new #MuddyWater campaign targeting critical infrastructure in 🇮🇱 Israel and 🇪🇬 Egypt, using a new backdoor – MuddyViper – and a variety of post-compromise tools www.welivesecurity.com/en/eset-rese... 1/7

02.12.2025 11:42 — 👍 6    🔁 6    💬 1    📌 0

@julianferdinand is following 20 prominent accounts