Threat actor
PicSix
Last fetched
PicSix is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
PicSix, also known as P6, is an Israeli cyber surveillance company based in Even Yehuda and run by former Israeli intelligence agents. It specializes in mobile interception technology. Their flagship product, P6Intercept, enables mass surveillance of hundreds of mobile phones simultaneously within its operational range. An Al Jazeera investigation uncovered that Bangladesh's Directorate General of Forces Intelligence (DGFI) acquired P6Intercept through an elaborate scheme designed to obscure the transaction's true nature. The deal involved multiple intermediaries: Sovereign Systems, a Singapore-based company, facilitated the purchase in Hungary, while James Moloney, an Irish national based in Bangkok, served as a middleman. To obscure the product's Israeli origin, the contract falsely listed Hungary as the country of manufacture. This arrangement allowed PicSix to conduct business with countries that typically avoid direct dealings with Israel. During product demonstrations to Bangladeshi intelligence officials, PicSix representatives reportedly conducted unauthorized phone interceptions in Hungary. Another notable product in their lineup is P6-FI5, a portable interception system that creates deceptive cell towers compatible with GSM, 3G, and 4G networks. This device employs a sophisticated strategy to bypass encryption: it deliberately disrupts encrypted applications on target devices, forcing users to switch to less secure, easily interceptable communication methods. Additionally, the system can deploy malware to any device connected to its counterfeit cell tower.
Techniques by tactic
No ATT&CK techniques are recorded for PicSix in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to PicSix today — this states the absence of a published link, not that PicSix has no infrastructure.
References
- https://www.aljazeera.com/news/2021/2/2/bangladesh-bought-surveillance-equipment-from-israeli-company
- https://www.technologyreview.com/2019/12/10/131646/cops-see-an-encryption-problem-spyware-makers-see-an-opportunity/
- https://www.officer.com/command-hq/technology/security-surveillance/covert-technology/product/12002695/picsix-ltd-p6intercept-a-passive-communications-interception-system
- https://www.middleeasteye.net/news/israeli-firm-sold-spyware-bangladesh-despite-export-ban
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from PicSix into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.