OilAlpha: Learn How Zimperium MTD Protects Against This New Threat
ID: ef457ea7-a384-5468-a50a-c754b2fd142b
STIX ID: report--ef457ea7-a384-5468-a50a-c754b2fd142b
Feed Name: Zimperium Blog
Zimperium reports on the OilAlpha group — a pro-Houthi-linked actor active since May 2022 that targets non-governmental, media, humanitarian, and development organizations across the Arabian Peninsula using social engineering via encrypted chat apps (e.g., WhatsApp), URL shorteners, and malicious Android apps. The group deploys spyware families including SpyNote and SpyMax (capable of SMS/call/media/GPS collection and resisting uninstallation) and njRAT (keystroke logging, screenshots, password theft, camera/microphone access, and remote control). Zimperium states its on-device ML detection engine covers the reported samples with zero-day coverage and its web filtering identifies the majority of reported C2-related URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
