Threat actor
Invasys
Last fetched
Invasys is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Founded in 2017 in Brno, Czech Republic, by former Norwegian government security adviser Kyrre Sletsjoe, Invasys is a discreet developer of surveillance technologies. The company develops ways for intelligence services to bypass smartphone encryption and improve their interception capabilities. Building on Sletsjoe's previous venture, Cepia Technologies, Invasys exploits vulnerabilities in GSM communication protocols, particularly the widely used A5 encryption. Invasys often markets its surveillance and interception products in trade shows like ISS, IPAS and IDEX.
Techniques by tactic
No ATT&CK techniques are recorded for Invasys in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Invasys today — this states the absence of a published link, not that Invasys has no infrastructure.
References
- https://www.intelligenceonline.com/surveillance--interception/2019/04/09/invasys-from-mobile-interception-to-cyber-intelligence,108352829-art
- https://www.haaretz.com/israel-news/security-aviation/2023-12-08/ty-article/.premium/at-defense-and-arms-expo-israeli-cyber-is-out-but-surveillance-tech-in/0000018c-49da-db23-ad9f-69da26e10000
- https://dfrlab.org/wp-content/uploads/sites/3/2024/09/Mythical-Beasts.pdf
- https://www.invasys.com/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Invasys into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.