ZooPark is a cyberespionage group targeting Android devices in the Middle East since 2015.
Analyst brief
ZooPark is a cyberespionage operation active since at least 2015, targeting entities in the Middle East. The group focuses on compromising Android devices and has deployed four generations of malware, with v4 being the latest version used in 2017. Their TTPs involve leveraging multi-stage Android malware to establish persistence and exfiltrate data. Defenders should prioritize mobile threat detection on Android platforms and monitor for IoCs related to these malware families, especially in sectors relevant to the Middle Eastern geopolitical landscape.
ZooPark
unknown
ZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind ZooPark infect Android devices using several generations of malware we label from v1-v4, with v4 being the most recent version deployed in 2017.