Libyan_Scorpions__2016__Hunting-Libyan-Scorpions-EN.pdf
ID: 3745b9d0-d1ae-4615-b862-f7974c7ec3d2
STIX ID: report--3745b9d0-d1ae-4615-b862-f7974c7ec3d2
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2016-09-17
Last Modified Date: 2016-09-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cyberkov's report details the 'Libyan Scorpions' espionage campaign (observed Aug 2016 with activity since Sep 2015) that spread a repackaged Android RAT via compromised Telegram accounts (e.g., 'Voice Massege.apk' masquerading as a voice message / URL Shortener). Analysis shows extensive Android RAT capabilities (camera, microphone, location, SMS, contacts, call logs, root escalation), a base64 config revealing C2 host winmeif.myq-see.com -> 41.208.110.46 (Libya), related Windows and Android samples (DroidJack/JSocket-like), open C2 services, and numerous IOCs (hashes, domains, IPs) for detection and mitigation.
