The Tal Dillian group produced and marketed the espionage software Predator in North Macedonia and Greece. This is known. What is not known is that the official bodies of the two countries attempted to cooperate on the issue, coming close to an agreement, before they abandoned their project due to the journalistic revelations of 2022.

The main points of the research
Inside Story in Athens and the Investigative Reporting Lab (IRL) in Skopje reveal today:
- The desire of the Greek government to legalize state use of spyware software according to the standards of North Macedonia.
- The content of the classified preliminary agreement drawn up in 2022 by the then commander of the EYP, Panagiotis Kontoleon, and the head of the Operational Technical Agency of Skopje( OTA) Zoran Angelovski, but not signed due to journalistic revelations about the use of Predator spyware in Greece.
- The open communication channel between the Greek prime minister's office under Grigoris Dēmētriadis and Intellexa, the company that markets the Predator spyware, which has infected or attempted to infect the mobile devices of Greek journalists, politicians, business executives, armed forces personnel and other individuals (who were simultaneously targeted by the legitimate but abusive links of the National Intelligence Service).
The hacker Rotem Farkas
The intention of the Greek government to legalize the use of espionage software was expressed as early as 2020 by one of the co-founders and developers of Cytrox, the company that created the best-known and notorious Predator, and which later was incorporated into the Intellexa group.
Born in January 1987 in Israel and raised in Tel Aviv by a Hungarian father and an Israeli mother, the 36‑year‑old Rotem Farkas had an early inclination toward programming. As he writes on his LinkedIn profile, for 2.5 years (January 2011 – June 2012) he provided freelance consulting services to banks and security companies, «bringing to the table the perspective of a hacker». Previously he had served for five years in the Israeli Defense Forces. People who know him boasted that as a member of the Israeli cyber‑unit he contributed to countering attacks on Israelis by Palestinian suicide bombers.
In March 2017, Rotem Farkas, along with six other Israeli entrepreneurs, founded Cytrox in Skopje. The initial funding came from the state-owned Israel Aerospace Industries (IAI). Cytrox, as revealed in December 2021 by a study by the Citizen Lab of the University of Toronto, is the company that developed the infamous Predator spyware that has been widely used in Greece against journalists, politicians, business executives, armed forces, etc. In 2018, Cytrox was acquired by Intellexa, a company owned by Tal Dilian, a former commander of an elite technological unit of the Israel Defense Forces, with Rotem Farkas remaining on the group's staff.
Cytrox and its products caught the attention of Tal Dilian, who decided to invest in it after his 2018 meeting with the then-new Prime Minister, Zoran Zaev. The North Macedonian government had known since 2017 that Cytrox was developing the Predator spyware on its territory, with the intention of distributing it elsewhere, but it claims it had not touched it. A source on the Skopje side told Inside Story and IRL that NATO had previously advised North Macedonia not to cooperate with the company.

The relocation to Greece
During the second half of 2020, Rotem Farcas's professional obligations on behalf of Intellexa lead him to decide to move to Paleo Faliro. Bringing with him the sports car Audi R8 with Hungarian plates that he was driving, he will settle in a luxurious apartment on the 8th floor with an unobstructed sea view. In the opposite building moves a close associate and employee at Intellexa's Greek offices, Roey Hayot, who, unlike Rotem Farcas, appears on Intellexa's payroll statements. The fact that Rotem Farcas was in Greece for Intellexa business is also demonstrated by the fact that on August 10, 2020, together with the company's founder Tal Dillian and another person, he travels for a few days by private plane from Athens to Larnaca and from there to the capital of Qatar, Doha.
People who were found at Rotem Farkas' house describe it as student-like, where in a room with empty shelves his desk with the computer and two huge monitors dominated.

The property in which Rotem Farkas lived in Paleo Faliro coincidentally belongs to a former New Democracy MP, a member of a shipping family with a large real estate portfolio managed by a real estate company. The rent for the apartment was paid by the KESTREL company, which is owned by Stavros Komnopoulos. The patriarch of the KESTREL group is a man well-known in equipment procurement, but also in the courts, since the 1980s. Rotem Farkas' apartment is not the only meeting point between KESTREL and Intellexa. As the inside story had revealed, RAFNAR, a company related to KESTREL, provided guarantees in a lease that Intellexa signed with a company of the Fais group in October 2020, for the offices it rented in Elliniko.
According to what was said in the inside story by people who wanted to remain anonymous and interacted with Rotem Farkas during the months he stayed in Greece, he described himself as a developer of software for defense against cyber attacks, also saying that he sells software to governments to monitor criminals – a description that matches that of spyware. They also report that Rotem Farkas claimed that he came to Greece after an invitation from the Greek government and while they had agreed on the use of the company's software, that he had met with various government officials and had received assurances from the Greek government that a law would be passed to legalize the use of the spyware. In May 2021 he left his house in Paleo Faliro without warning and moved back to Israel. According to his acquaintances, he told them that there was some kind of disagreement with his partners in the company and he was thinking of leaving permanently by selling his shares.
We addressed questions to Rotem Farkas about his alleged contacts with government officials and the content of their conversations, but we did not receive a response.
The interest of the Mitsotakis government in the retroactive legalization of spyware
Everything claimed by Rotem Farcas in casual talks he had in the second half of 2020 with his Greek friends, regarding the government's intention to legalize the use of spyware, appears to be confirmed by the fact that the Mitsotakis government towards the end of 2020 had come into contact with the Operational Technical Agency Skopje (Operational Technical Agency Skopje – OTA), which has been the competent authority since 2018 for declassifications in North Macedonia.
Person with good knowledge of the content of contacts between Athens – Skopios, which started at the end of 2020, reports in inside story and IRL that the Greek side was interested in learning from North Macedonia how the OTA functioned and how the country's secret services and other law enforcement authorities used espionage software in a legal manner. North Macedonia expressed interest in various cyber‑security issues and in the digitisation of the Greek public sector with the responsible Ministry of Digital Governance.
The OTA is not a secret service, like the EYP, but the fruit of the painful experience that the citizens of North Macedonia had in repeated surveillance scandals. The most recent one concerned the period of the Gruevski government, when more than 20,000 people were monitored between 2008 and 2015. The targets included civil society activists, politicians from all parties, journalists, diplomats, and businessmen.
After the fall of Groveski, the US and the European Union imposed on the government of North Macedonia to create a technical service –politically neutral that would be subordinate to the parliament and not to the political authority– through which the requests of the secret, police and customs services for monitoring the country's citizens would pass. The institutional framework of North Macedonia also allows the use of spyware with various security safeguards against possible abuse, at least on paper.
The desire of the Mitsotakis government to legalize the use of espionage software, expressed in the second half of 2020, actually follows chronologically the «experimental» tests of the Predator spyware, which, as the Inside Story has written, had started in Greece as early as August 2019, shortly after the New Democracy party came to power. When the contacts between the Hellenic Police (EYP) and OTA began, Intellexa had already been operating in Greece for six‑seven months. It was founded in March 2020 and the first counterfeit domains that mimic well‑known Greek websites in order to trap mobile individuals in Greece with Predator were created in July 2020. We know that journalist Thanasis Koukakis was among the first targets of Predator in the long list of names that includes, among others, politicians, business executives and armed forces officials. His first targeting occurred on July 31, 2020, a date on which the EYP had already lifted the confidentiality of his communications and was listening to the journalist’s conversations, for «national security reasons».
As Investigate Europe and Reporters United recently revealed, the Mitsotakis government has advocated for the pan-European use of spyware against journalists – “for reasons of national security.”
The confidential cooperation memorandum for the exchange of classified information between the National Intelligence Service and the Operational Technical Agency
People with knowledge of the content of contacts between Athens – Skopios report in inside story and IRL that the first in‑person meeting between the Greek and Macedonian side took place in early 2021, at the level of EYP and OTA officials.
According to some information, later that same year a meeting of the Macedonian side with the Minister of Digital Governance Kyriakos Pierrakas in Athens followed. From Pierrakas' environment they deny any meeting with representatives of the OTA. According to another source, the only contact Pierrakas had with officials from North Macedonia was the meeting that took place in Athens with the Vice President of North Macedonia, Nikola Dimitrov, which on the Greek side concerned the digitization of the state.
In February 2022, a new meeting took place between Kontoleon and Angelovski in Thessaloniki, which led to the drafting of a preliminary agreement between the two commanders a month later, in March 2022. The draft was communicated to the office of Prime Minister Kyriakos Mitsotakis.
«The two organizations will take all necessary measures to preserve the very existence of this MoU (note: Memorandum of Cooperation) […] confidential» writes draft of the pre‑agreement that has been seen by Inside Story and IRL and was drafted in the first half of 2022 with the purpose of being signed by the heads of the Greek EYP and the Macedonian OTA. «The cooperation will be managed personally by the heads of the organizations», we read in the same draft dated March 2022, a month before the revelations by Inside Story about the trapping of journalist Thanasis Koukaki’s phone with the Predator spyware.
«EYP and OTA […] will cooperate and share unclassified as well as classified information based on the following mutually agreed upon:
1. Participants will collaborate to improve professional development in cybersecurity and to create a cybersecurity skills base, among other things through possible initiatives related to mutual recognition of qualifications and diversity. […]
2. The participants will establish and maintain an operational dialogue and will identify opportunities for cooperation, in order to enhance the ability of both to protect their citizens from malicious activities in cyberspace.
3. Requests for information can be submitted by both sides, and the response will be based on the level of security and will be subject to the applicable rules and regulations governing the disclosure of classified information.
4. Requests for information will be limited to technologies related to cyber threats, terrorism, criminal activity, which participants consider threats to their national interests.
5. In the event that an immediate threat is identified from any side, pursuant to this memorandum of agreement, the organizations will share the information as soon as possible and will assist the partner in eliminating the threat for the benefit of both countries».
The existence of this pre‑agreement between the Hellenic Police (EYP) and the local government (OTA) for cybersecurity was confirmed by former EYP commander Panagiotis Kontoleon, in his closed‑door testimony to the investigative committee regarding the surveillance on September 15, 2022. According to information, it is reported that he stated that the Greek government has been informed about this pre‑agreement.
This also results from the draft that Inside Story has seen, which is addressed not only to Kontoleon but also to the Office of the Prime Minister of Greece. The head of the office at that time, until his resignation on August 5, 2022, was Kyriakos Mitsotakis' nephew, Grigoris Dimitriadis, who was removed from his position in the aftermath of the revelation of the monitoring of the current PASOK leader, Nikos Androulaki, by the National Intelligence Service.

Άτομο με γνώση των διαπραγματεύσεων μεταξύ Αθήνας και Σκοπίων ανέφερε στο inside story ότι το Μνημόνιο Συνεργασίας μεταξύ ΕΥΠ και ΟΤΑ τελικά δεν υπογράφηκε, διότι μεσολάβησαν τα δημοσιεύματα για τη παρακολούθηση του κινητού του δημοσιογράφου Θανάση Κουκάκη με το λογισμικό της Intellexa.
We officially addressed inquiries to the Hellenic Police and the former Panagiotis Kontoleon and Grigoris Dimitriadis regarding the meetings and the content of the document, but we received no answer.
The Municipality, in its responses, officially confirms that there was contact with the Hellenic Police, concerning cyber security and digitisation issues:
The Operational Technical Service (OTA) is an autonomous and independent state body. Within the scope of its responsibilities and activities, OTA, among other things, carries out collaborations and contacts with many domestic, foreign, and international authorities, which are conducted through official communication channels. Such were the meetings [of OTA] with the leadership of the Greek National Intelligence Service (EYP) that took place in the first half of 2022, as the competent bodies for monitoring communications in both countries. In these meetings, classified information was not disclosed and no documents were signed. No Cooperation Memorandum was signed either.
The topic of the meetings was the exchange of experiences in the field of system digitization, towards improving security during digitization, which includes cybersecurity, for which the presentation on the digitization process of Greek society was extremely useful, which […] has made remarkable progress and results.
For the visits and the results of the conversations, the Parliamentary Committee [of Northern Macedonia] was informed about the implementation of oversight of communication monitoring measures, as well as government representatives».
The editor from Intellexa
During his submission to the investigative committee of the Greek Parliament regarding the surveillance in September 2022, Panagiotis Kontoleon (who had also resigned due to Androulaki), after confirming the existence of a pre‑agreement between the Hellenic Police and the local authorities, is said to have rushed to emphasize that the Hellenic Police has no connection with Intellexa, the company that markets the Predator spyware software.
The inside story and the IRL have seen evidence that this statement is false.
The draft of the pre‑agreement that we have seen in electronic form has a subtle but historically significant electronic trace that proves that Intellexa not only has a direct relationship with the NSA, but also with the office of Prime Minister Kyriakos Mitsotakis. This particular document, which was to be signed by the services of two states, Greece and North Macedonia, contains textual corrections from a former senior official of the Israeli Ministry of Defence, who after his retirement collaborated with Intellexa.

His name is Nir Ben MosheNir Ben Moshe | LinkedIn (written in the draft corrections in Hebrew) and it remains as a trace if the “change tracking»” is enabled for the changes made in the electronic document. Source reports that the draft was sent to Intellexa.

Nir Ben Moshe is no stranger to Israel, having held several key government positions. In 2015, he was appointed head of a special unit in the Defense Ministry, known as Malmab, which is responsible for the security of the Defense Ministry, Israeli arms industries, and entities in Israel involved in the development and production of weapons of mass destruction, as well as for the means of defense against such weapons. Malmab, due to the secret nature of its activities and its close ties to the Israeli internal security agency Shin Bet, is sometimes described as Israel's fourth intelligence agency (after Shin Bet, Mossad, and the Israeli military's secret services). Nir Ben Moshe left the Israeli Defense Ministry in 2021 and turned to the private sector. In May 2022, Israeli reports reported that he was considering collaborating with Tal Dilian's company.
Commenting on this professional move, sources of the Israeli security establishment in Israel told the press that the relocation of Nir Ben Moshe to Tal Dillian’s side «is legal but it stinks. It is a coster but presents some ethical issues». The Israeli security establishment, from which the founder of Intellexa also comes, accuses Tal Dillian of having used the knowledge he acquired as commander of an elite technological unit of the Israeli Army to found companies that manufacture products for cyber attacks that infiltrate mobile phones and that he moved his companies to Cyprus (note also later to Greece) to avoid supervision by the Israeli Ministry of Defense, i.e., his former employer Nir Ben Moshe.
Ταξιδιωτικά έγγραφα που έχει δει το inside story δείχνουν ότι o Νιρ Μπεν Μοσέ το πρώτο δεκαήμερο του Μαρτίου 2022 επισκέφτηκε την Αθήνα και όταν έκανε τις διορθώσεις στο προσχέδιο ΕΥΠ – ΟΤΑ για λογαριασμό της Intellexa βρισκόταν στο Ισραήλ. Τα ταξίδια μεταξύ Ελλάδας και Ισραήλ ήταν συχνά. Ακόμα, στις 23 Μαρτίου 2022 πετάει από Ελλάδα για Αλβανία και πίσω και την ίδια μέρα αναχωρεί ξανά από Ελλάδα προς Τουρκία – είναι άγνωστο αν αυτά τα ταξίδια έγιναν για προσωπικούς ή επαγγελματικούς λόγους. Η τελευταία φορά που επιβιβάστηκε σε πτήση από την Ελλάδα ήταν τον Οκτώβριο του 2022, όταν αναχώρησε για τις ΗΠΑ. Με βάση όσα γράφει στο προφίλ του στο Linkedin, από τον Μάρτιο του 2022 έχει ιδρύσει μία συμβουλευτική εταιρεία εμπνευσμένη από τα αρχικά του ονόματός του (NIRBM), της οποίας η ιστοσελίδα δεν εμφανίζει περιεχόμενο.
Another element that seals Nir Ben Moshe's professional relationship with Intellexa is that on April 12, 2022, he appears to be traveling from Larnaca to Athens on a private plane that has been linked to Tal Dilian and with which, as the inside story has revealed in a report together with Lighthouse Reports and Haaretz, surveillance technology was delivered to Sudan from somewhere in the European Union (the equipment was found in the hands of one of the most notorious and terrifying paramilitary groups in the world, the Rapid Support Forces).
An individual from the secret services of North Macedonia, who spoke under anonymity in Inside Story and IRL, reports that he does not know Nir Ben Mose, nor does he know why a copy of the draft that was to be signed by the heads of EYP and OTA was found in the hands of Intellexa and was even corrected by its associate. “The Greek side had mentioned that it has a contractor, but they never mentioned the name Intellexa»,” he says.
Nir Ben Mose, Intellexa, Grigoris Dimitriadis, Panagiotis Kontoleon and EYP did not answer the relevant questions we addressed to them.
The production of this research was supported by a grant from the Investigative Journalism for Europe Funding cross-border investigative journalism in Europe | IJ4EU (IJ4EU).
Source of information: insidestory.gr
