Israeli Predator Spyware in Pakistan — Amnesty’s Warning
Amnesty International’s discovery of Israeli spyware known as Predator in Pakistan revealed a quiet digital war. Pakistan and Israel have no diplomatic relations, and Pakistan does not formally recognise the Israeli state. The “Intellexa Leaks” probe revealed a Predator strike involving a WhatsApp link against a human rights lawyer in Balochistan. This mid-2025 incident was the first known Predator strike carried out on Pakistani territory.
The investigation found links between the operation and Intellexa, a surveillance consortium that provides Predator platforms to governments around the world. Israel and Pakistan have no diplomatic relations. Any spyware of Israeli origin in Pakistan is rapidly explosive, both politically and technically. The Pakistani officials have denied the charges vehemently, calling the report “malicious” and saying that there is not an iota of truth in it.
Intellexa Leaks: Predator in Pakistan
The “Intellexa Leaks” project blends internal sales decks, training videos and other sensitive company material with forensic work by Amnesty’s Security Lab. In Pakistan, a lawyer in Balochistan got a suspicious WhatsApp message from an unknown number with just one shortened link.
Researchers investigated that link and concluded, based on the behaviour of the server and the structure of the one-time infection URL, that it was an attempted Predator attack. Both were consistent with previous Predator campaigns in other countries, providing additional support for the conclusion that Israeli Predator spyware in Pakistan had at least been used to target, even if the infection was unsuccessful.
The leaks also reveal the way Intellexa controls its customers’ systems. Training material shows staff remotely logging into at least 10 Predator customer platforms using commercial remote-administration tools that allow them to see live targeting and, at times, data from infected devices. This information is important for Pakistan. If any agency in the country ever used Israeli Predator spyware in Pakistan, Intellexa itself could see, or shape, some of that surveillance.
Spyware like Predator could subtly alter Pakistan’s military and defense posture in dangerous ways. Senior officers, planners and nuclear custodians using compromised smartphones could find their movements tracked, chats read and operations anticipated before they happen. Sensitive procurement discussions, test schedules or deployment plans could leak in real time, not years later.
The loss of secrecy would undermine deterrence, impair crisis signalling and sow distrust among allies. Pakistan’s armed forces are capable of more than just defending networks. Adversaries watching every digital move must see every handset, every app, and every casual voice note as a potential source of intelligence.
Israeli-made viruses and spyware
Israeli spyware and malware helped define the cyber battlefield we know today. Stuxnet destroyed centrifuges in the initial attack on Iran’s Natanz site, bringing the nuclear programme to a halt. Often linked to the same technical lineage, Duqu shifted the focus to the stealthy intelligence side, quietly hoisting documents and system information to support later operations.
Flame developed into a regional-wide-area espionage operation, collecting audio, keystrokes, screenshots and network data. Pegasus, marketed as a legitimate interception tool, has been used against journalists, activists and politicians, giving near-complete control over smartphones and drawing global condemnation once it was revealed. Then Predator. Same playbook. Pulling messages, pulling files, turning on microphones, and spreading fear among critics.

Pakistan’s Cyber Fightback
Other than Predator, Pakistani analysts worry about Israeli-linked tools like Pegasus and other mercenary implants that may already be probing local networks. Such platforms can secretly track officials’ contacts, listen in on conversations and follow cross-border communications in near real-time.
In response, Pakistan’s cybersecurity community, from state SOCs to private telecom teams, is slowly hardening its posture. They enforce stricter device policies, run native threat-hunting scripts and conduct controlled malware simulations to learn enemy tradecraft. Local low-key research on defensive beacons and countersurveillance codes tries to apply the same asymmetric logic to intruders.
The Israeli spyware Predator in Pakistan is technically following the same pattern as in Europe, the Middle East and Africa. Predators usually begin with “1-click” operations: the target receives a crafted link via SMS, WhatsApp, email or social media. When opened, the link exploits vulnerabilities in Chrome or Safari to get the first code execution and downloads the full spyware implant.
Once installed, Predator can extract just about anything of operational value: encrypted chats from Signal and WhatsApp, saved passwords, email, contact lists, call logs, photos and precise location history. The malware can also activate the microphone, turning the smartphone into a live room bug.
Israeli Predator spyware in Pakistan sends the pilfered data through a web of obfuscation, hiding the origin before it is transferred to a server in the customer’s country in an effort to hide the identity of the operator, the report said. This architecture limits the chances of attribution while maintaining latency to a level that enables near real-time surveillance.
From 1-Click to Zero-Click Warfare
Another leak describes “Aladdin”, a clever way for Intellexa to bypass the usual 1-click tricks. Rather than waiting for a victim to click on a link, Aladdin uses commercial ad networks to deliver hidden exploit chains. These chains are activated when a malicious ad loads on a targeted device in an app or browser. In practice, that means Israeli Predator spyware can infect a phone in Pakistan without any tapping or clicking.
That reach is very tempting to a state concerned about leaks from lawyers, journalists or security officials. But that power carries a huge collateral risk that extends far beyond any single target or national security threat. Advertising infrastructure often spans multiple jurisdictions and regions. When Aladdin is on those rails, foreign devices may be travelling on the same hostile infrastructure without realising it.
Denials and Diplomatic Fallout
The security establishment in Islamabad has publicly rejected Amnesty’s findings. Senior officials have termed the narrative of the Intellexa leaks as ‘misleading’, ‘politically motivated’ and ‘not in line with Pakistan’s own security policies’. Their resistance signals the potential sensitivity of Israeli Predator spyware in Pakistan, which has no formal relationship with Israel and where any perceived cooperation could be politically damaging domestically.
It is difficult to ignore Intellexa’s track record elsewhere. Predator has already been deployed in Greece and in Egypt. The United States has sanctioned Intellexa and its affiliated companies for targeting officials and civil society around the world. In 2023, Greece’s Data Protection Authority fined Intellexa €50,000 for hindering its probe into spyware abuses.
Separately, Google’s Threat Intelligence teams said Predator had targeted “several hundred accounts” in several countries, including Pakistan. Kaspersky said its systems detected an average of 500,000 malicious files a day in 2025, and the growth of spyware was higher than for several other categories of threats. These developments frame Israeli Predator spyware in Pakistan in a broader global boom in mercenary surveillance and advanced intrusion tooling.

Impact on Pakistan’s Civil–Military System
The cost to Pakistan’s security establishment is not just humiliation or a dent in its reputation. Any actor using Israeli Predator spyware in Pakistan would have access to military, nuclear or strategic communications. This is a particularly disturbing prospect as many officials still use regular smartphones for sensitive conversations. The first known victim is a human rights lawyer from Balochistan, a region long plagued by insurgency and disappearances.
This profile matches that of global Predator campaigns, which tend to focus on civil society rather than hardened terrorist or military networks. There’s a pattern here that space, electronic warfare and reconnaissance professionals will recognise. Surveillance now ranges from spy satellites to the lawyer’s smart phone, dramatically shrinking the battlefield. Overall, whoever controls the sensors, the data they collect and the rules governing its use has power.
Hardening against Predator-class threats
Amnesty’s findings are real whether Islamabad accepts them or not, and so is the technical threat of Predator-class spyware. Agencies’ response takes three forms:
- Device Hygiene and Segregation: Move sensitive operations out of commercial messaging applications. Require senior commanders and negotiators to use hardened, segregated devices.
- Exploit-path reduction: Blunt Aladdin vectors by patching mobile OS and browsers. Limit ad-tracking and third-party Javascript. Consider ad-blocking at the network edge.
- Policy and oversight: Establish a clear, court-supervised process for any domestic use of commercial spyware, or publicly disavow such tools and advocate for multilateral controls.
Conclusion
The Israeli Predator spyware story in Pakistan is a stark warning to analysts and readers of Defense News Today. It demonstrates that cyber power is now a fundamental component of stability, in addition to missiles, drones and satellites. States that do not address this domain, either technically or legally, risk losing much more than just data – they risk losing leverage and trust.
References
- https://securitylab.amnesty.org/latest/2025/12/intellexa-leaks-predator-spyware-operations-exposed/
- https://www.dawn.com/news/1959162/pakistan-uses-highly-invasive-israeli-spyware-says-amnesty-report
- https://www.kaspersky.com/about/press-releases/the-number-of-the-year-kaspersky-detected-half-a-million-malicious-files-daily-in-2025
- https://www.amnesty.org/en/latest/news/2025/12/intellexa-spyware/
