GuardZoo Malware Targets Over 450 Middle Eastern Military Personnel
ID: a82b0369-b945-574d-b28f-e23adc6c94e8
STIX ID: report--a82b0369-b945-574d-b28f-e23adc6c94e8
Feed Name: The Hacker News
Lookout observed an ongoing surveillanceware campaign (GuardZoo) since at least October 2019 that targets military and related personnel in several Middle Eastern countries; the Android malware—derived from leaked Dendroid RAT code—supports 60+ commands for extensive data collection (photos, documents, navigation/mapping files), is distributed via WhatsApp and direct APK downloads, uses ASP.NET C2 servers and dynamic DNS resolving to YemenNet IPs, and has been attributed to a Houthi-aligned actor given targeting, lures, infrastructure, and logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
