ZeroHour
CyberScooppublished ()ingested @timstarks

Predator spyware demonstrates troubleshooting, researcher

criticalMalwareimportance 55
Full article676 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

It’s the latest batch of revelations about what makes the Intellexa-made spyware stand out from competitors.

Listen to this article

0:00

Learn more.

J Studios, Getty Images

Predator spyware operators have the ability to recognize why an infection failed, and the tech has more sophisticated capabilities for averting detection than previously known, according to research published Wednesday.

Jamf Threat Labs found from an analysis of a Predator sample that it has an error code system that can alert operators to why an implant didn’t stick, with “error code 304” signifying that a target was running security or analysis tools.

“This error code system transforms failed deployments from black boxes into diagnostic events,” Shen Yuan and Nir Avraham wrote for the company. “When an operator deploys Predator against a target and receives error code 304, they know the target is running security tools — not that the exploit failed, not that the device is incompatible, but specifically that active analysis is occurring.

“This has direct implications for targeted individuals: if security analysis tools like Frida are running, Predator will abort deployment and report error code 304 to operators, who can then troubleshoot why their deployment failed,” they continued.

Furthermore, the capability to detect specific security tools reveals more about Predator’s workings.

“The inclusion of netstat is noteworthy — it suggests Predator is concerned about targets who might be monitoring their own network connections, not just researchers with specialized tools,” the researchers wrote. “A privacy-conscious user simply checking their network connections would trigger this detection.”

And Predator suppresses crash logs that can help detect infection attempts, Jamf concluded.

It’s the second time in as many months that researchers have uncovered capabilities that differentiate Predator, made by Intellexa, from competitors.

Jamf said the results of its analysis show that Predator is interested in dodging both spyware researchers and security products, and overall point to better anti-analysis capabilities than those that have been previously documented.

More Scoops

The OpenAI logo is displayed on a smartphone screen placed on a reflective surface, photographed using a slow exposure with a motion blur effect, in Creteil, France, on May 12, 2026. Daybreak is an AI-powered cybersecurity service designed to detect, analyze, and remediate software vulnerabilities more quickly. (Photo by Samuel Boivin/NurPhoto via Getty Images)

What the Hugging Face breach reveals about defense in the age of agentic AI

We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying…

Stelios Kouloglou arrives for a meeting with the police commissioner at the police headquarters on Dec. 3, 2019 in Valletta, Malta. (Photo by ANDREAS SOLARO / AFP) (Photo by ANDREAS SOLARO/AFP via Getty Images)

Someone infected a spyware probe overseer with spyware

Researchers say AI just broke every benchmark for autonomous cyber capability

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/predator-spyware-demonstrates-troubleshooting-researcher-dodging-capabilities/