Overview
- Teixeira Cândido, then head of the Syndicate of Angolan Journalists, received WhatsApp messages in April–June 2024 and was infected after opening a link on May 4.
- Amnesty’s Security Lab found Predator operating on his device that day and tied the intrusion to Intellexa via known infection servers and domains, the first confirmed use in Angola.
- Cândido’s iPhone was cleared of the spyware after a reboot hours later, and 11 subsequent infection links sent to him appear to have failed.
- Researchers traced Predator-linked infrastructure in Angola to March 2023 and assess that Cândido’s case likely forms part of a broader campaign.
- The U.S. sanctioned Intellexa and associates in March 2024, three executives were removed from the sanctions list on Dec. 30, 2025, and confirmed abuses have been documented in countries including Egypt, Pakistan and Greece.