Houthi rebels are operating their own GuardZoo spyware
ID: 6ea76986-227a-5f3b-83f4-a9e69c07a901
STIX ID: report--6ea76986-227a-5f3b-83f4-a9e69c07a901
Feed Name: The Register (Security)
Threat Score
GuardZoo is a Dendroid RAT–derived Android surveillanceware attributed to Houthi-linked operators, active since at least 2019 and distributed via WhatsApp and direct downloads using social engineering; it collects geolocation data (KMZ, WPT, TRK), photos, documents, and device configuration and uses a bespoke C2 and dex-based updates to maintain persistence and stealth, primarily targeting Yemeni military personnel and some regional military staff.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
