HomeSecurityPro-Houthi Gang Targets Yemen with Android Spyware

Pro-Houthi Gang Targets Yemen with Android Spyware

Pro-Houthi gang targets at least three humanitarian organizations in Yemen with spyware software for Android , designed to collect sensitive information.

pro-houthi spyware android

These attacks, attributed to a cluster of activities codenamed OilAlpha, include a new set of malicious mobile applications with their own supporting infrastructure, according to Recorded Future's Insikt team.

Among the targets of the ongoing campaign are CARE International, the Norwegian Refugee Council (NRC) and the King Salman Humanitarian Aid and Relief Center of Saudi Arabia.

See more: Apple warns iPhone users in 98 countries about spyware attacks

“The OilAlpha threat group likely remains active and is carrying out targeted actions against humanitarian and human rights organizations operating in Yemen and potentially across the Middle East,” the cybersecurity.

OilAlpha was first recorded in May 2023, during a spying campaign targeting development, humanitarian, media, and non-governmental organizations in the Arabian Peninsula. These attacks leveraged WhatsApp to distribute malicious Android APK files, promoting them as being associated with legitimate organizations such as UNICEF, ultimately leading to the installation of the SpyNote (also known as SpyMax) malware.

The most recent wave of attacks, detected in early June 2024, involves apps claiming to be related to humanitarian aid programs and masquerading as entities such as CARE International and NRC, both active in Yemen. Once installed, these apps – which host the trojan – request intrusive permissions, facilitating the theft of victims’ data.

OilAlpha's activities also include collecting credentials through fake login pages impersonating these organizations, aiming to obtain user login information. There are suspicions that the goal is espionage by accessing the accounts of the affected organizations.

“Houthi fighters have consistently sought to restrict the movement and delivery of international humanitarian aid, benefiting from the taxation and resale of aid supplies,” Recorded Future reported. “A possible explanation for the observed cyber targeting is intelligence gathering to facilitate control over who receives aid and how it is delivered.”

Read also: Hackers exploit MSHTML vulnerability to distribute MerkSpy spyware

pro-houthi spyware

This development comes just weeks after Lookout revealed the involvement of another threat actor aligned with the pro-Houthi gang, a spyware software business that provides the Android data collection tool, GuardZoo, to targets in Yemen and other Middle Eastern countries.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS