logo

OilAlpha Malicious Applications Target Humanitarian Aid Groups Operating in Yemen

ID: faff2f12-d465-5fa0-a772-b7c5787be9c7

STIX ID: report--faff2f12-d465-5fa0-a772-b7c5787be9c7

Feed Name: Recorded Future Blog

Threat Score
70/100

Date Published: 2024-07-09

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group reports that OilAlpha, a likely pro-Houthi threat actor, continues an active campaign targeting humanitarian organizations (including CARE International, the Norwegian Refugee Council, and the King Salman Humanitarian Aid and Relief Centre) using malicious Android applications functioning as remote access trojans and a credential-harvesting portal (kssnew.online); the report details discovered APKs, their invasive permissions, observed credential theft techniques, and provides mitigation recommendations such as MFA, social-engineering awareness, and use of threat intelligence tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.