logo

OilAlpha Malicious Applications Target Humanitarian Aid Groups Operating in Yemen

ID: 4db7839a-a9e0-415a-81ce-fdc7a97bc1f2

STIX ID: report--4db7839a-a9e0-415a-81ce-fdc7a97bc1f2

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2024-07-08

Last Modified Date: 2024-07-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
OilAlpha, a likely pro-Houthi threat actor, is actively targeting humanitarian and human-rights organizations operating in Yemen and the Middle East using malicious Android applications (RATs such as SpyMax/SpyNote) and credential-theft portals; the report documents multiple APK samples with SHA256 hashes, associated DDNS domains, IP addresses, a credential theft domain (kssnew.online), and identified targets including CARE International, the Norwegian Refugee Council, and the King Salman Relief Centre, and provides mitigations such as MFA, anti-phishing training, and sandbox analysis.