Loading…
Loading…
Intellexa S.A. (Athens, Greece) and Intellexa Limited (Dublin, Ireland) form the commercial and corporate-holding layer of the Intellexa Consortium, the alliance of surveillance-technology vendors that markets and distributes the "Predator" mobile spyware. Predator is a mercenary spyware tool capable of zero-click device compromise — extracting messages, call logs, photos, location data, and activating the microphone and camera without any user interaction. It has been documented by Citizen Lab and Amnesty Tech targeting civil society activists, journalists, and government officials across multiple continents.
Cytrox Holdings Zrt. (Budapest, Hungary) and Cytrox AD (Skopje, North Macedonia) are the technical developer entities behind the Predator spyware itself. Cytrox was co-founded by former NSO Group engineers and built the underlying exploit chain before being acquired into the Intellexa Consortium. Listing both the developer (Cytrox) and the distribution/holding layer (Intellexa) across all four corporate domiciles closes the multi-jurisdictional re-export routing structure that commercial spyware vendors typically use.
License requirement: All items subject to the EAR require a license from BIS; the review policy is presumption of denial — functionally a ban on all US-origin technology transfers to these entities.
Statutory basis: Section 744.11 of the Export Administration Regulations, which covers entities acting contrary to US national security or foreign policy interests.
Context: This rule followed a July 2022 Citizen Lab report and a December 2022 Meta Threat Intelligence report documenting Predator deployments against targets in Europe, the Middle East, and Sub-Saharan Africa. BIS published this rule concurrently with the Commerce Department's broader push to expand Entity List use against commercial surveillance technology vendors, following the earlier November 2021 listing of Israel's NSO Group (developer of Pegasus) and Candiru.
effectively cut off from US-made chips, cloud infrastructure, and development tools. Given the extent of US-origin technology in the global software stack, this severely constrains product development and maintenance.
North Macedonia), marking one of the first times BIS has targeted commercial surveillance-tech companies domiciled within or adjacent to the EU. Signals that allied-country origin provides no insulation when the technology is used for malicious surveillance.
holding company + distribution subsidiaries) across all domicile jurisdictions simultaneously, rather than relying on a single-entity listing that can be circumvented via corporate restructuring.
semiconductors, or cloud services to commercial surveillance-tech vendors operating in Europe: expanded due-diligence obligation to screen against the full Entity List, including allied-country entities.
action to restrict the companies' operations domestically.
in 2023-24 noted attempts to rebrand or spin off entities to evade controls.