The case of Artemis Seaford, a former META (Facebook) executive with dual Greek and American citizenship, who, as the New York Times reported, was simultaneously monitored by the National Intelligence Service (NIS) and the illegal Predator spyware of the company Intellexa, is the latest and possibly the most striking evidence that the two surveillance methods originate from the same principals.
This particular victim is the third in a row, after “patient zero” journalist Thanasis Koukakis and political leader and MEP Nikos Androulakis, who have been shown to be a common target of both the EYP and the spyware, with the government continuing to deny any official involvement with Predator. “I have categorically said both personally and as a government many times that anything related to illegal software has no connection to any official Greek authority,” government spokesman Yannis Economou said on Monday, March 20, speaking on MEGA’s main news bulletin, following the NYT report.

However, the coincidences in the Koukakis, Androulakis and Seaford cases, as well as the sequence of events, clearly point in one direction: the state (or entities and individuals who acted unofficially on behalf of state agencies).
See also: Predator inside story: SMS the key to the wiretapping investigation
Predator: A software par excellence for government use
At this point, we should clarify that the use of spyware by private individuals was and remains illegal; in fact, the current government, in the wake of the wiretapping, tightened the penalties for the use of such (expensive) tools-weapons by private individuals, but at the same time conveniently institutionalized in the same law the procurement of spyware by the state, an action that is diligently kept secret by the government spokesman. At the same time, the company Intellexa, which markets Predator (on its website) as well as its founder Tal Dilian, a former high-ranking official in the Israeli army, claims that it sells its products exclusively to governments and state agencies around the world.
| The articles of Law 5002/2022 The provisions for individuals: 1. Whoever unlawfully intercepts or in any other way interferes with a device, connection or network providing fixed or mobile telephony services or with a system used for the provision of such services, with the aim of himself or another being informed or recording on a material medium the content of a telephone conversation between third parties or communication data (movement and location) is punished with imprisonment for up to ten years. The same penalty is also imposed for the act of the previous paragraph when the perpetrator records on a material medium the content of his telephone communication with another person, without the express consent of the latter. […] A new article 370F is added to the Criminal Code (Law 4619/2019, A' 95) as follows: "Article 370F Prohibition of trafficking in software, surveillance devices and other data 1. Anyone who produces, sells, procures for use, imports, exports, possesses, distributes or otherwise traffics software or devices , with the ability to intercept, record and any type of extraction of content or communication data (movement and location), with which the acts of article 370A can be committed (ed.: Violation of the confidentiality of telephone communication and oral conversation) shall be punished with imprisonment for at least two years. 2. Anyone who, without right and with the intention of committing one of the crimes of articles 370B, 370C, (ed.: Illegal access to an information system or to data and Illegal access to an information system, respectively) of paragraphs 2 and 3 of article 370D and article 370E, produces, sells, procures for use, imports, exports, possesses, distributes or otherwise traffics passwords or access codes or other similar data, with the use of which it is possible to gain access to the whole or part of an information system, shall be punished with imprisonment for at least two years. The provision for the state: Procurement of software and monitoring devices by the State By presidential decree, issued within three months of the entry into force of this, upon a proposal from the Ministers of Citizen Protection, National Defense, Justice and Digital Governance, the conditions under which the conclusion of contracts by state structures for the procurement of software or monitoring devices of article 370F of the Criminal Code for the fulfillment of their purposes, as well as additional terms of their use, are determined. |
As reported in the inside story by the senior analyst at the Citizen Lab of the University of Toronto, Bill Marzak, who has been dealing with spyware for years and confirmed the infection of Thanasis Koukakis' mobile phone with Predator: "We have not […] seen a case in which a powerful spyware like Predator […] has been sold to a private company for its own use. Intellexa may sell other products and services to private companies, but I would be shocked if they sold Predator to private companies. […] it is difficult to imagine a scenario where a private company could legally use Predator. Furthermore, this type of software usually costs many millions of dollars, which a private company probably could not pay."
As the inside story has revealed , the Predator was purchased by the Greek side for 7 million euros. The head of the Personal Data Protection Authority, Costas Menudakos, revealed in a recent hearing at the PEGA committee of the European Parliament, which investigates the use of spyware against European citizens in EU member states (including Greece), that the authority's checks so far show that 300 infected messages to 100 recipients. It is difficult to determine which private individual could allocate so many millions to purchase Predator (even if the company sold it to non-governmental/state entities) and, most importantly, who would be interested in such mass-scale monitoring of quite diverse individuals (journalists, politicians, businessmen, business executives, state officials, etc.).
See also: NYT reveals what happened in the Greek Predator scandal
The sequence of events in the Seaford case
In August 2021, the EYP requested the declassification of Artemis Seaford's communications; this was during the period when she was still working at META (facebook), in the field of cybersecurity and the security of social media users from threats. Her declassification includes speech and text messages (made through the telecommunications provider's network, i.e. simple calls and SMS) and lasted until the summer of 2022, which means that there were successive two-month renewals. In September 2021, while she was legally connected to the EYP, her mobile phone was infected with the Predator spyware. As Citizen Lab, which conducted the technical inspection, certified, Artemis Seaford's mobile phone had been turned into a perfect bedbug for at least three months, i.e. from September to December 2021.
“Predator can take screen captures, record user input, and activate the device’s microphone and camera. This allows attackers to monitor any activity that occurs on or near a device, such as conversations taking place in a room. Predator also allows its operator to record text messages sent or received (including those sent via “encrypted” apps, or apps that allow messages to disappear, such as WhatsApp or Telegram) as well as regular and VoIP phone calls (including phone calls via “encrypted” apps),” we read in the Citizen Lab report dated December 16, 2021, which revealed to the general public the existence of this particular spyware, which in addition to the confidentiality of communications, also blatantly violates the privacy of the individuals targeted.

Another very interesting thing that Citizen Lab's analysis of Artemis Seaford's mobile phone found was the text message with the malicious link that she received and infected her phone as soon as she clicked on it. Shortly before her infection, she had made a vaccination appointment through the emvolio.gov.gr platform. As is normal, as the days approached, she received two reminders on her phone with the details of her vaccination. The message was sent by "EMVOLIO", it stated the date, time of vaccination and the vaccination center and was accompanied by the official link "emvolio.gov.gr". A few hours after the second reminder, Artemis Seaford received a new message on her phone, this time from "EMVOLIO GOV". The SMS had all the correct details (time, day and vaccination center) and urged her to confirm her appointment by clicking on a link identical to the legitimate one, which turned out to be malicious. The only difference between the legitimate “emvolio.gov.gr” and the malicious link that eventually infected her device with Predator was a dash between the words “emvolio” and “gov”.
The question that arises is how the Predator operators knew the exact details of Seaford's vaccination and, using this information, managed to trap her mobile phone. Based on the sequence of events we have described, the only logical answer that can be deduced is that the information obtained from the legal connection of the EYP was used: that is, the legal SMS that she received from the official state vaccination platform on her mobile phone a few hours earlier. So the two monitoring methods were used complementary. The possibility that this information fell into the hands of other perpetrators (and not the state) through some leak of sensitive personal data from the emvolio.gov.gr platform, which millions of people have used for their vaccination, seems completely unlikely. Moreover, according to reliable information from Inside Story, the Ministry of Digital Governance has carried out technical checks and has ruled out the possibility that there was an incident of breach of the vaccination platform. Doctors and pharmacists in the country can also have access to a person’s vaccination details through the official platform emvolio.gov.gr, however, they need to type in the person’s AMKA. However, even if it is assumed that the Predator operators knew Artemis Seaford’s AMKA and were in close collaboration with a pharmacist or doctor, it is extremely unlikely that they would have achieved such good synchronization between the second legitimate reminder of her vaccination appointment and the malicious identical SMS, which were only a few hours apart from each other, and not during working hours. Both SMS were sent after midnight.
See also: How Sudan is connected to the Predator scandal that is shaking Greece
The cooperation of the two monitoring methods (legal connection by EYP and illegal via Predator) and the utilization of the information collected by the first to infect devices with the second exponentially increases the chances of the victim being deceived, thinking that they are receiving an expected and innocent message and ultimately clicking on the malicious link, thus making the spyware even more dangerous.
Inside Story also reports on another case of a person whose legitimate SMS received on his mobile phone was used against him in an attempt to infect his device with Predator. This is a high-ranking public official who had placed an order with a well-known shoe store, received a confirmation of his order on his mobile phone, and later received a malicious message related to the same order.
Thanasis Koukakis targeted by Predator twice, once simultaneously with the EYP
The sequence of events, as Reporters United has also highlighted, is crucial and highlights the common center of legal and illegal surveillance in the case of Thanasis Koukakis, who, as we reveal today, had been targeted by Predator twice. The first time was on July 31, 2020, a date on which the Hellenic Security Service had already declassified his communications and was listening to the journalist’s conversations for “national security reasons.” At that time, he received an SMS on his mobile phone that read “Thanasis, did you see this, the guys have escaped” and immediately after that a new text message with a link from a fake Greek news site that led to an article titled “Sea loan for the health of suckers.”.
According to the report by Reporters United, on June 1, 2020, with order number E2402/2020, the EYP submitted a request to Cosmote to lift the confidentiality of a mobile number that the journalist had with the provider. The lifting of confidentiality was requested for two months – from June 1 to August 1, 2020 – citing national security reasons. On July 13, the EYP, with order number E3077/2020, requests an extension of the declassification of the same number, again for reasons of national security and for a period of two months, until October 1, 2020. However, a month later, on August 12, the EYP, with order number E3580/2020, suddenly requests a cessation of the declassification, that is, before the second two-month period of surveillance expires. On August 12, 2020, the day that the EYP requested that the declassification of Koukakis be stopped, the journalist filed a complaint with ADAE to inform it whether his communications on two mobile numbers and one landline were being monitored. On March 10, 2021, after the confirmation of the wiretaps, ADAE addressed the Prosecutor of the EYP regarding whether the conditions of the law for informing the journalist about the lifting of his confidentiality were met. On March 31, just 20 days after ADAE's question to EYP, the government brought the amendment that changes the law and ADAE is now prohibited from disclosing the surveillance to the citizen. The regulation has retroactive effect and therefore covers the Koukakis wiretaps. At noon on July 12, 2021, Koukakis received a seemingly innocent SMS from a Greek mobile phone. "Thanasis, do you know about this issue," read the message, which was accompanied by a link to blogspot.edolio5[.]com, an identical URL to the blog edolio5.blogspot[.].com. One click was enough to install the spyware.
The sequence of events in the Androulakis case also seems to be incriminating for the government. From Koukakis to Androulakis: A new twist in the Predator spyware case. He became the target of the Predator spyware with a text message he received on September 21, 2021. The attempted infection (he did not click on the malicious link) was certified by an analysis by a competent technical team of the European Parliament in July 2022. As was revealed last summer by an accidental government leak that led to the resignations of Dimitriadis-Kontoleontas, Nikos Androulakis had also been put on a "legal" connection by the EYP shortly after the failed attempt to infect him with the spyware. In fact, the infected link they sent him was from the same forged domain that infected Thanasis Koukakis' cell phone, namely blogspot.edolio5[.]com.
Source: insidestory.gr
