Article Details
Scrape Timestamp (UTC): 2025-12-31 05:19:43.944
Source: https://thehackernews.com/2025/12/us-treasury-lifts-sanctions-on-three.html
Original Article Text
Click to Toggle View
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware. The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a commercial spyware known as Predator, from the specially designated nationals list. The names of the individuals are as follows - Hamou was sanctioned by OFAC in March 2024, and Harpaz and Gambazzi were targeted in September 2024 in connection with developing, operating, and distributing Predator. It's currently not known why they were removed from the list. Harpaz is said to be working as a manager of Intellexa S.A., while Gambazzi was identified as the owner of Thalestris Limited and Intellexa Limited. Thalestris, Treasury Department said, held the distribution rights to the spyware, and processed transactions on behalf of other entities within the Intellexa Consortium. It's also the parent company to Intellexa S.A. Hamou was listed by the Treasury as one of the key enablers of the Intellexa Consortium, working as a corporate off-shoring specialist in charge of providing managerial services, including renting office space in Greece on behalf of Intellexa S.A. It's not known if these individuals are still holding the same positions. At that time, the agency said the proliferation of commercial spyware presents a growing security risk to the U.S. and its citizens. It called for the need to establish guardrails to ensure the responsible development and use of these technologies while balancing human rights and civil liberties of individuals. "Any hasty decisions to remove sanctions from individuals involved in attacking U.S. persons and interests risk signaling to bad actors that this behavior may come with little consequences as long as you pay enough [money] for fancy lobbyists," said Natalia Krapiva, senior tech legal counsel at Access Now. The development comes merely weeks after an Amnesty International report revealed that a human rights lawyer from Pakistan's Balochistan province was targeted by a Predator attack attempt via a WhatsApp message. Active since at least 2019, Predator is designed for stealth, leaving little to no traces of compromise, while harvesting sensitive data from infected devices. It's typically delivered via 1-click or zero-click attack vectors. Similar to NSO Group's Pegasus, the tool is officially marketed for counterterrorism and law enforcement use. But investigations have revealed a broader pattern of its deployment against civil society figures, including journalists, activists, and politicians. An investigation from Recorded Future published this month found continued use of Predator despite increased public reporting and international measures. "Several key trends are shaping the spyware ecosystem, including growing balkanization as companies split along geopolitical lines, with some sanctioned entities seeking renewed legitimacy through acquisitions while others shift toward regions with weaker oversight," the Mastercard-owned company said. "Furthermore, rising competition and secrecy surrounding high-value exploit technologies are heightening risks of corruption, insider leaks, and attacks on spyware vendors themselves."
Daily Brief Summary
The U.S. Treasury's OFAC has lifted sanctions on three individuals associated with Intellexa, the company behind Predator spyware, without disclosing the reasons for this decision.
These individuals, previously sanctioned in 2024, were involved in the development, operation, and distribution of the Predator spyware, raising questions about ongoing oversight.
Intellexa's Predator spyware, similar to NSO Group's Pegasus, is marketed for counterterrorism but has been used against journalists, activists, and politicians, sparking human rights concerns.
Recent reports indicate Predator's continued use, despite increased scrutiny and international regulatory efforts aimed at curbing misuse of such surveillance tools.
The removal of sanctions could signal to other actors that financial influence might mitigate consequences for activities threatening U.S. interests and citizens.
The situation underscores the need for robust international frameworks to manage the ethical development and deployment of commercial spyware technologies.
Recorded Future's investigation notes rising competition and secrecy in the spyware market, increasing risks of corruption and insider threats.