Immediately after the publication of our first report on the Predator Files, the Greek government, as we are able to know, was alarmed by the announcement that the Washington Post was participating in the journalistic investigation, among the 15 media partners. The main reason for the government's concern about what the internationally renowned American newspaper will publish is found in today's publication.

The Predator Files reveal today that between February and June 2023, the Twitter account @Joseph_Gordon16 (now X) targeted over 50 individuals and organizations in Europe, the US and Asia using Predator. The alleged victims of the surveillance included high-ranking officials, media and journalists, such as:
- President of the European Parliament Roberta Mezzola
- French MEP and Chairman of the European Parliament's Fisheries Committee Pierre Karleskind
- three senators and one member of the U.S. House of Representatives
- German Ambassador to the United States Emily Haber
- Albania's Minister of Tourism Mirela Kubaro, Tirana Mayor Elion Velijai and the country's former Minister of Justice Etilda Jonaj
- the president and foreign minister of Taiwan (Tsai Ing-wen and Joseph Wu, respectively)
- the French media outlet France24, three journalists from the American CNN and Vietnamese journalist Hoa Le Trung.
(More details about the victims of surveillance in the new report by Amnesty International's Security Lab, published today, October 9, 2023, in collaboration with the Predator Files).
Happy Golden New Year
In the second part of our investigation, we uncovered conversations between Nexa and Intellexa executives in a WhatsApp group chat about the sale of the Predator to Egypt on December 31, 2020. On the same day, Tal Dillian, the mastermind behind Intellexa and Predator, asked the French at Nexa if there was “news from the Khmer Rouge,” using the nickname for members of the Communist Party in Cambodia to refer to neighboring Vietnam. The historical connection is obvious: The Khmer Rouge was formed in 1968, initially as an offshoot of the Viet Cong.
The answer came shortly after New Year's Day, at 1:40 in the morning: "The contract with VN [Vietnam] has been signed," wrote Nexa's number two, Olivier Bobeau.
"Wow!", Dillian celebrated.
"Fishtail"»
The classified documents show that the $5.6 million contract with Vietnam was for “eavesdropping solutions” and was codenamed “Fishnet.” The choice of a fish for the deal is likely linked to Vietnam’s long history of fishing, which, as we will see, played a significant role in the selection of surveillance victims.
See also: Predator Files: A series of reports on Predator, Intellexa and wiretapping in Greece
The leak documents that the Predator was purchased by MOPS, an acronym for Vietnam's Ministry of Public Security, which has been implicated in other computer hacking cases and is a tool for persecuting dissidents and human rights defenders.
Nexa tried to conceal the sale of the Predator to Vietnam. That is why the contract was negotiated by Advanced Middle East Systems (AMES), a Nexa subsidiary based in Dubai. The deal also involved Hong Kong-based Delsons Hong Kong Ltd, which - as an intermediary - bought the Predator from AMES and sold it to the Vietnamese Ministry of Public Security. On November 1, 2021, Delsons transported three pieces of the eavesdropping equipment to the Asian country. The manufacturer of the equipment was a company called “AM”. This is the acronym used in Nexa documents to refer to AMES.
The Greek dimension of the issue is as follows: As we revealed in the second part of the investigation, in June 2021 Salies admitted to French authorities that they were considering doing research and development in Greece for a new software . The above answer was given when French authorities asked him if the reason AMES was established in the United Arab Emirates was to secure software export licenses bypassing European legislation, since France may have blocked the sale of Predator to the Vietnamese regime. His answer, to argue that they were following EU rules, brought Greece to the center of the Intellexa galaxy, since it was essentially presented as an EU member state where companies associated with Predator and other spying software would operate.
We reached out to Salies and Bobo. They did not answer whether they themselves provided the equipment that ended up in Vietnam through Delsons. However, they vaguely claimed that in all cases they “complied with applicable legislation and obtained permits from the competent control authorities” for their exports.

"Someone will lose their job"
The targeting from Vietnam was not done via SMS, as in the Greek attacks, but via Twitter. @Joseph_Gordon16 responded to posts from would-be victims, publicly posting the infected link. As victims had to click on it to be trapped by Predator, it remains unknown how many of them were targeted .Predator Files has contacted targets to ask if they would like to check their devices to see if they were being tracked.
Software experts told us that they were surprised by the trapping method, as it has two significant drawbacks: First, public targeting can lead to trapping not only the would-be target, but also any other user who clicks on the infected link. The problem becomes obvious when we consider that accounts of EU institutions, such as the European Commission, which has over 30,000 employees. Second, public targeting can be more easily detected compared to SMS targeting.
"Someone is going to lose their job over this story," Citizen Lab researcher John Scott-Railton told EIC (the network that coordinates the Predator Files investigation and in which Reporters United participates), commenting on the sloppiness of the attack.
The new report from Amnesty International’s Security Lab, published today alongside the Predator Files, says the surveillance attempts were likely carried out by “agents of the Vietnamese authorities.” This assessment is also supported by Citizen Lab and Google’s Analytics Team. “We assess that this attack is linked to a government authority in Vietnam,” Google commented.
The fish stinks from the head down
Vietnam had strong motives for monitoring the victims we mentioned above.
Take the case of the EU, 12 of whose executives were targeted via Predator, according to Amnesty International.
See also: The Predator Files revelations: How Athens became a hub for Intellexa wiretapping
The attack on EU officials appears to be linked to the fact that in 2017 the EU warned Vietnam about its failure to tackle illegal fishing. This warning was the "yellow card", which, if the situation did not change, would be followed by the "red card", i.e. an embargo would be imposed on Vietnam and it would not be able to export its fishery products to the EU.
Fishing is one of the main sources of income for Vietnam. In 2021 alone, it exported around €750 million worth of fishery products to the EU. The Asian country therefore had a direct interest in monitoring EU officials and authorities who have influence over fisheries policy. This is exactly what @Joseph_Gordon16 did, targeting the Commission's Directorate-General for Climate Action, the Directorate-General for Environment and the head of the Directorate-General for Fisheries, Charlina Vytseva, using Predator.
For the same reason, it is believed that French MEP Pierre Karleskind, chairman of the European Parliament's Fisheries Committee, was also targeted. In 2022, Karleskind voted against lifting the yellow card against Vietnam for illegal fishing. At the time, he did not imagine that the state he voted against would target him shortly afterwards with the Predator. "My position must not have pleased the Vietnamese government," he commented in the investigation.
The MEP said he did not remember clicking on the infected link. However, he pledged to take action against the targeting: “Behaving in this way towards an MEP is unacceptable, it is an attack on democracy. I will inform the French counter-intelligence authorities. And when your article is published, I will ask the Vietnamese ambassador to the EU to come to office for explanations. I am considering legal action. I will consider all options. As a politician, I must exercise restraint. However, one thing is certain: I will not let this go on like this.”
MEP Karleskind's stance is in stark contrast to the silence of the Greek political system on the issue of wiretapping. Although Greek ministers have been officially informed by the Hellenic Data Protection Authority (HDPA) about their targeting via Predator, they have not resorted - as they should have - to justice to protect their rights and the public office they held when they were being monitored. Among them, Messrs. Gerapetritis, Plevris, Hatzidakis (also monitored by the EYP), Chrysochoidis, Georgiadis, Dendias.
European Parliament President Metsola, also a target of the Predator attack, declined to comment on the case before the investigation was published.
Vietnamese journalist Hoa Le Trung was also targeted by Predator. He is the director of Thoibao, one of Vietnam’s largest opposition websites with more than 20 million monthly visits. Le Trung told Predator Files that he did not click on the infected link that targeted him on February 9, 2023. However, he expressed concerns about the protection of employees and sources. If Vietnamese authorities were to gain access to his phone, “it would put my employees and contacts at risk,” the journalist told the investigation. “You can’t sell [hacking software] like this to countries like Vietnam.”
Among the targets are three CNN journalists. Two are based in Taiwan. The third is Jim Sciuto, a host and senior national security analyst.

Panic after Predator Files questions
The Predator Files were addressed to Vietnam and Intellexa. Our questions were not answered. But they seem to have caused panic, as immediately after they were sent in mid-September, the @Joseph_Gordon16 account was shut down, and some of the technical equipment used for Predator mobile targeting was immediately taken out of service.
“Over 70% of known Predator servers have been taken offline since mid-September,” Amnesty International Security Lab Director Donha Osearbhaiel said in the research.
See also: Predatorgate: What the SMS-traps received by businessmen, ministers and journalists said
American goals and Greece
Let's now look at Maximos' concern about the Predator Files and the Washington Post.
While Intellexa's galaxy was developing multiple connections with Greece, one of the company's key eavesdropping software, Predator, ended up in the hands of Vietnam, which would even target high-ranking US officials.
Our investigation shows that Vietnam targeted three US senators and one member of the House of Representatives with Predator. Among them, two very influential politicians: First, Democratic Senator Chris Murphy, a member of the Foreign Relations Committee and responsible for Middle East and Asian affairs. Second, Republican Senator Michael McCaul, head of the Foreign Affairs Committee.
Representatives for the two senators told the Washington Post that they did not click on the infected links. However, a Biden administration source told the investigation and Predator Files that the recent decision on July 18, 2023, to Intellexa and Cytrox as suspected illegal espionage agents by the U.S. Department of Commerce was accelerated when the U.S. became aware of the surveillance efforts by Vietnam.
We recall from the second part of our investigation the multiple connections of Greece with the Intellexa galaxy: Nexa was thinking of organizing R&D for specific software in Greece. Nexa, which at the same time was an irreplaceable partner of Tal Dillian, the largest shareholder of Intellexa, which was also based in Athens, with its second largest shareholder here, Felix Bigzio, who found himself in the same network of corporate transactions with Mr. Grigoris Dimitriadis, who was politically responsible for the EYP, which had the same surveillance goals as the Predator, which Intellexa with export licenses from the Mitsotakis government.
In this light, Greece is presented as one of the hub countries that, together with other states, allowed the spread of Intellexa and Predator, to such an extent that the software was eventually used against the Americans. The reaction of the latter against corporate executives and government officials who allowed and facilitated this development is now logical to worry Athens.
#PredatorFiles is a cross-border investigation involving 15 media outlets, based on confidential documents obtained by the French Mediapart and the German Der Spiegel, coordinated by the EIC (European Investigative Collaborations) network and in collaboration with Amnesty International’s Security Lab. The investigation involves EIC members NRC, Politiken, Expresso, Le Soir, De Standaard, VG, infolibre and Domani in collaboration with the media outlets Shomrim (Israel), Die Wochenzeitung (Switzerland), Reporters United (Greece), Daraj Media (Lebanon) and the Washington Post (USA).
Source: www.reportersunited.gr
