OilAlpha Malicious Applications Target Humanitarian Aid Groups Operating in Yemen
ID: faff2f12-d465-5fa0-a772-b7c5787be9c7
STIX ID: report--faff2f12-d465-5fa0-a772-b7c5787be9c7
Feed Name: Recorded Future Blog
Recorded Future’s Insikt Group reports that OilAlpha, a likely pro-Houthi threat actor, continues an active campaign targeting humanitarian organizations (including CARE International, the Norwegian Refugee Council, and the King Salman Humanitarian Aid and Relief Centre) using malicious Android applications functioning as remote access trojans and a credential-harvesting portal (kssnew.online); the report details discovered APKs, their invasive permissions, observed credential theft techniques, and provides mitigation recommendations such as MFA, social-engineering awareness, and use of threat intelligence tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
