Home/Threat Actor/Wintego Systems
Threat Actor

Wintego Systems

wintego_systems · israel · active since 2011-01

Wintego Systems Ltd. (Israel.

founded approximately 2011) is an Israeli commercial surveillance vendor (PSOA) that develops the CatchAll WiFi-network-interception platform for government law enforcement and intelligence clients; CatchAll provides WiFi network traffic interception in proximity to targeted individuals (messaging-app traffic, web browsing capture), credential extraction from WiFi- transmitted authentication traffic, adversary-in-the-middle positioning via evil-twin access-point impersonation, and WiFi network authentication brute-forcing capabilities; operationally distinct from mobile-spyware-focused Israeli PSOA peers (NSO Group / Pegasus, Candiru / DevilsTongue, Paragon Solutions / Graphite, QuaDream / REIGN, all curated separately) by virtue of WiFi-network-interception product category rather than mobile-device-implant-deployment; examined by the European Parliament PEGA Committee (2022-2023) in the broader Israeli surveillance vendor ecosystem governance context.

thin public technical documentation relative to NSO Group / Pegasus and other major mobile-PSOA vendors.

curated for Israeli PSOA ecosystem completeness (WiFi-interception sub-ecosystem coverage) alongside Wintego's product-category-distinct Israeli PSOA peers.

israel confidence: medium 10 aliases
Sigma rules166 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Wintego Systems Ltd. (Israel.

founded approximately 2011) is an Israeli private sector offensive actor (PSOA), a commercial surveillance vendor that develops, markets, and sells WiFi-network-interception platforms and associated intelligence-collection tools to government law enforcement and intelligence clients under a lawful-interception commercial model. Wintego occupies a distinct position in the Israeli commercial surveillance vendor ecosystem: unlike the mobile-spyware- focused Israeli PSOA peers (NSO Group / Pegasus, curated at nso_group_pegasus.yaml.

Candiru / Saito Tech / DevilsTongue, curated at candiru_saito_tech.yaml.

Paragon Solutions / Graphite, curated at paragon_solutions_graphite.yaml; QuaDream / REIGN, curated at quadream.yaml), Wintego's primary product category is WiFi-network-interception rather than mobile-device-implant-deployment. The product-category distinction operationally distinguishes Wintego from the mobile-spyware-dominant Israeli PSOA market and positions the company within the smaller WiFi-and-network-interception sub-ecosystem of the commercial surveillance vendor market. The CatchAll WiFi-network-interception platform, Wintego's signature commercial product, provides marketed capabilities for: (1) WiFi network traffic interception in proximity to targeted individuals, capturing transmitted data including messaging-app traffic and web browsing.

(2) credential extraction from authentication traffic transmitted over WiFi networks.

(3) adversary-in-the-middle positioning on target WiFi networks via evil-twin access-point impersonation and ARP cache poisoning tradecraft.

(4) WiFi network authentication brute-forcing for access to protected networks. The operational capability profile positions CatchAll as a network-proximity-attack tool, operationally distinct from remote-mobile-implant-deployment tools (NSO Pegasus, Intellexa Predator) that operate via remote message delivery and zero-click exploitation chains, and operationally distinct from forensic mobile-device-access tools (Cellebrite UFED) that operate via physical-device access workflows. The company has not publicly disclosed its client list or deployment jurisdictions. Industry analysis and investigative journalism reporting (Forbes 2017 disclosure, Haaretz, Reuters, European Parliament PEGA Committee inquiry 2022- 2023) has documented Wintego as one of the Israeli surveillance technology vendors selling products to international government clients. The European Parliament PEGA Committee inquiry examined the Israeli surveillance vendor ecosystem in which Wintego operates as part of broader European commercial surveillance governance investigation, providing governance-context backdrop for assessing the cluster's commercial operations. The PSOA governance significance of Wintego, like all commercial surveillance vendors in this curated corpus, is that government clients nominally purchasing CatchAll for lawful interception of criminal suspects have, in the broader PSOA ecosystem pattern, been documented to direct surveillance tools against journalists, human rights defenders, opposition politicians, and civil society members in contexts inconsistent with stated lawful- interception justifications. No publicly-available technical report has definitively attributed specific CatchAll deployments against named civil society victims with the same evidentiary density as Citizen Lab's Pegasus forensic reports, Wintego's public attribution footprint is thinner than NSO Group's but analytically significant in the Israeli PSOA market context. Wintego operations are subject to Israeli defense export control regulations administered by the Israeli Ministry of Defense's Defense Export Controls Agency (DECA / DECA-MOD), consistent with the broader Israeli PSOA ecosystem governance framework. This actor entry is curated as a thin-documentation entry relative to flagship PSOA entries in this corpus, the public technical disclosure record for Wintego Systems is significantly less dense than for NSO Group, Intellexa, Paragon Solutions, Candiru, or Cellebrite. The entry is structurally significant for PSOA ecosystem completeness (providing coverage of the Israeli WiFi-network-interception sub-ecosystem distinct from the mobile-spyware-dominant Israeli PSOA market) rather than for deep technical tradecraft analysis. Analysts requiring technical depth on Israeli PSOA tradecraft should prioritize the NSO Group / Pegasus, Paragon / Graphite, Candiru / DevilsTongue, QuaDream / REIGN, and Cellebrite entries.

Aliases

10
wintego_systemswintego systemswintego systems ltdwintegocatchall_operatorscatchall surveillancehelios_operatorsisraeli-psoa-wintegopsoa-wintegowifi interception vendor

Notable Campaigns

3
2022-2023European Parliament PEGA Committee, Israeli Surveillance Vendor Ecosystem Context (2022-2023)
2017Forbes Investigative Disclosure, Wintego Systems CatchAll Product (2017)
2011-2025Israeli Defense Export Control (DECA) Governance Context

Attribution & Reporting

Attributed by
Citizen Lab (University of Toronto Munk School)Forbes investigative reportingHaaretz investigative reportingReuters investigative reportingEuropean Parliament PEGA CommitteeAccessNowAmnesty International Tech LabIsraeli Ministry of Defense (DECA / export licensing context)Privacy InternationalRecorded Future
Key reporting
reportForbes: Wintego Systems Investigative Disclosure (2017)
reportEuropean Parliament PEGA Committee Final Report (May 2023), Israeli surveillance vendor ecosystem context
reportCitizen Lab: Israeli Commercial Surveillance Vendor Research (multiple years)
reportHaaretz: Israeli Surveillance Industry Investigative Coverage
reportReuters: Wintego Israeli Spyware Firm Investigative Reporting
reportPrivacy International: Commercial Surveillance Vendor Ecosystem Documentation
reportMalpedia Actor Profile: Wintego Systems

Operational

State sponsor

Wintego Systems Ltd. is an Israeli private sector offensive actor (PSOA), a commercial surveillance vendor based in Israel that develops, markets, and sells WiFi-network- interception platforms and associated intelligence-collection tools to government law enforcement and intelligence clients under a lawful-interception / government-exclusive commercial model. The company is headquartered in Israel and was founded approximately 2011. Wintego's signature commercial product is "CatchAll", a WiFi-network- interception platform marketed as enabling government clients to intercept WiFi network traffic in proximity to targeted individuals, capture transmitted data including messaging- app traffic and web browsing, and extract authentication credentials transmitted over WiFi networks.

The company's stated business model is government-exclusive lawful interception, the company markets CatchAll and adjacent products exclusively to government customers (law enforcement agencies, intelligence services, military intelligence) as tools for criminal investigations and national security operations. The company operates within the broader Israeli commercial surveillance vendor ecosystem that includes NSO Group (curated at nso_group_pegasus.yaml, Pegasus mobile spyware), Candiru / Saito Tech (curated at candiru_saito_tech.yaml, DevilsTongue Windows spyware), Paragon Solutions (curated at paragon_solutions_graphite.yaml , Graphite mobile spyware), QuaDream (curated at quadream.yaml, REIGN mobile spyware), Cellebrite (curated at cellebrite.yaml, mobile device forensics), and additional Israeli surveillance technology companies. Wintego's operational positioning is operationally distinctive within the Israeli PSOA ecosystem in that its primary product category is WiFi-network-interception rather than mobile- device-implant-deployment, operationally distinct from the mobile-spyware-focused product categories of NSO Group, Candiru, Paragon, and QuaDream.

The company does not publicly disclose its client list or deployment jurisdictions. The company has been documented in investigative journalism reporting (Forbes, Haaretz, Reuters, and the European Parliament PEGA Committee inquiry) as one of the Israeli surveillance technology vendors selling products to international government clients.

Motivations
commercial_surveillance_vendor, government_wifi_interception_tools_sales, lawful_interception_commercial_model, psoa_commercial_operations
Sectors
Regions

Detection Blind Spots

20 techniques
Across this actor’s 20 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)13/20 · 65%
Analytics (MITRE CAR)2/20 · 10%
Runtime / container (Falco)3/20 · 15%
File / malware (YARA)1/20 · 5%
Network (Suricata/Snort)3/20 · 15%
Vuln scan (Nuclei)0/20 · 0%

Atomic Test Plan

9 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin