OilAlpha Hackers Target Humanitarian and Human Rights Organizations
ID: ab84fff4-5ec6-5aeb-804b-131f073f966f
STIX ID: report--ab84fff4-5ec6-5aeb-804b-131f073f966f
Feed Name: Cyber Press
OilAlpha, a pro-Houthi cyber actor, is targeting humanitarian organizations in Yemen with malicious Android applications masquerading as legitimate aid programs; these apps request invasive permissions (camera, microphone, SMS, contacts) and function as RATs, while credential-harvesting portals hosted on domains like kssnew.online/kssnew.com are used to collect stolen credentials. The campaign appears to use social engineering (likely WhatsApp) to distribute malware, risking theft of login data, photos, audio, SMS and contacts and potentially enabling manipulation of aid distribution; organizations are advised to enforce strong passwords, multi-factor authentication, and user training to detect suspicious apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
