Eavesdropping Greece and how much does it cost to buy Predator spyware? Documents leaked on the internet show how much it costs and at what price Intellexa sells predator spyware in European countries. The leaked documents concern an offer by Intellexa in Spain – probably to the Spanish secret services. From this we can estimate the cost of selling the corresponding solution in Greece. According to the documents – offers, Intellexa's services include support for, among other things, iOS Remote Code Execution 0day exploit for eavesdropping on Apple iPhones with the total cost of the solution amounting to €8,000,000.

See Also: Predator surveillance Parliament debates on Friday
The documents/offers were leaked on Twitter by the vxunderground , which covers security and hacking cases worldwide. The documents were also shared on the hacking forum xss.is.
Inside Story writes about Intellexa: Predator The "spy" that came from Cyprus

Eavesdropping: Predator spyware purchase and price
The following message appears to have been posted on the xss.is Forum about a month ago:

A forum user advertises the fact that he has the source code for a cyber-surveillance software with exceptional capabilities. After mentioning the features of the software at the end, he emphasizes that he can negotiate with anyone he wants for an “8 figure” price, while in his advertisement he states that he only accepts serious offers and that the software he has in his hands is superior to the equivalent of the NSO Group.
It is important to note that the suite in question, according to the advertiser on the hacking forum, includes “the ability to create and send malicious links from multiple domains” (does this sound familiar??). In fact, according to sources, the user who advertised the malware in question on the hacking forum was reportedly asking for €50,000,000 , while the same sources report that after a few days he was kicked out of the forum for unknown reasons. It has not been clarified whether the profile in question was an attempt to sell the monitoring software without the knowledge of the Intellexa company by former executives or employees, or whether the source code of the software had been intercepted by hackers from its systems (as had previously happened to a similar company).
The leak of the entire proposal has been posted [here]
Days after the publication of the relevant advertisement, important screenshots of documents from an offer by the company Intellexa in Spanish were leaked on the hacking forum xss and on twitter accounts ! The offer, according to the leaked screenshots, is dated July 1, 2022 and refers to the company's NOVA platform, with the ability to intercept Android and iOS devices .

The company Intellexa, according to a report by the Jerusalem Post in 2021, "provides a holistic solution for cyber defense and data analysis," whilespecifying 2019 as the year of its founding.

The documents leaked with Intellexa's offer in Spain accurately describe the capabilities of the spyware.

Intellexa's NOVA platform, therefore, for "remote data capture" (aka hacking) on Android and iOS devices includes:
- The malware is delivered by downloading a 1-click exploit, which requires the victim to click once on any malicious link sent by the attacker.
- The feature is available on both Android and iOS devices
- Supported versions Android 12 (and 18 months back) and iOS up to 15.4.1 (and 12 months back)
- It is possible to simultaneously infect 10 devices shared between iOS and Android
- It can be used for a total of 100 “infections” of devices. It is noteworthy that it reports successful infections/victims as “magazines”, indicating that its sellers are using this as a “cyber-weapon”
- The geographical coverage of the software is within the country for which it was purchased, covering the SIM cards of the local provider.
- The platform includes a platform for analyzing the received data (fusion & analytics system), searches and management of the data that is intercepted (of course we are talking about personal data)
- The entire Intellexa solution is available on a turnkey basis and all software is provided exclusively by Intellexa
- Cloud services, domains and anonymization processes are provided exclusively by the customer (governments)
- A 12-month warranty on the proper functioning of the platform is available.
The total price of the platform according to Intellexa's proposal is 8,000,000e
The offer also includes an indicative topology of the installation of the Intellexa monitoring platform as shown below (in Spanish):

The image above shows a logical diagram of the infrastructure required for the use of the interception platform (cloud, anonymization, operator terminals) in order to achieve successful use against the victims of interception.
Additionally, elsewhere in the offer, the devices that can be infected by the spyware are listed. As one can see, it includes all devices.




The platform also appears to offer support services, occasional updates, and training.
The proposal files as published on the xss.is forum have been posted by unknown people [here].


The proposal is valid until August 15, 2022 and it is not clear whether the Spanish government ultimately proceeded with the purchase of the solution.


Additionally (without the reliability of the following photos having been verified so far, i.e. whether they relate to the Intellexa platform or another similar platform), an XSS.IS user shared a demonstration/demo that supposedly relates to surveillance software that targets the latest versions of Android and iOS using the CNN news website (!).

It is worth noting that the European Commission, according to the analysis it has made public regarding the Pegasus software, had referred extensively to the case of Spain.


And in the Spanish case, it is worth noting that the authorities stated “that everything was done legally by the respective National Intelligence Service.”
Update1 – 26/8/2022:
The source of the leak on hacking forum xss.is has returned with a new post stating the following:

He states that he has at his disposal a remote execution code (exploit CVE-2022-32893) regarding Apple Webkit which was fixed by Apple exactly 5 days ago. In fact, he is pricing this particular code at 2,500,000e! Many on the forum report that the user is probably trying to mislead, lie or troll something that has not been clarified so far.
SecNews continues its in-depth technical investigation into Predator and its malicious activity in Greece related to wiretapping and will soon return with data and revelations to discuss! It is worth mentioning that since the first publication/disclosure of the above (which was made exclusively by our website before being retransmitted by other accounts and websites), our website has received over 30,000 cyber attacks within the last 72 hours.
Attacks from unknown parties using anonymization & IP hiding techniques have been successfully repelled in their entirety, with full recording of the origin characteristics of each attack by international cybersecurity and attack response providers that support our website (as shown in the diagram below, which we received thanks to Cloudflare).

It seems that revelations are probably disturbing!
