logo

Pro-Houthi Group Targets Yemen Aid Organizations with Android Spyware

ID: 651fc2cb-a46f-5550-9c4c-3c257412db5f

STIX ID: report--651fc2cb-a46f-5550-9c4c-3c257412db5f

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-07-19

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Recorded Future’s Insikt Group identified an active campaign by the OilAlpha cluster targeting humanitarian organizations in Yemen with malicious Android apps (SpyMax/SpyNote) and fake credential-harvesting pages. The attackers distribute APKs via WhatsApp posing as legitimate relief organizations to collect intrusive permissions, steal data and login credentials, likely to support intelligence-gathering related to aid distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.