OilAlpha Malicious Applications Target Humanitarian Aid Groups Operating in Yemen
ID: 4db7839a-a9e0-415a-81ce-fdc7a97bc1f2
STIX ID: report--4db7839a-a9e0-415a-81ce-fdc7a97bc1f2
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2024-07-08
Last Modified Date: 2024-07-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
OilAlpha, a likely pro-Houthi threat actor, is actively targeting humanitarian and human-rights organizations operating in Yemen and the Middle East using malicious Android applications (RATs such as SpyMax/SpyNote) and credential-theft portals; the report documents multiple APK samples with SHA256 hashes, associated DDNS domains, IP addresses, a credential theft domain (kssnew.online), and identified targets including CARE International, the Norwegian Refugee Council, and the King Salman Relief Centre, and provides mitigations such as MFA, anti-phishing training, and sandbox analysis.
