ZooPark
Malware family · 10 sample(s) · 10 indicator record(s) · 4 signing certificate(s) · Active 2016-01-27 → 2018-09-11 (experimental)
About ZooPark
ZooPark is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the Middle East (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| androidupdaters.com | domain | 91659d5f35a8… | 2017-04-08 |
| androidupdaters.com | domain | f1ab53d9728d… | 2018-09-11 |
| entekhab10.xp3.biz/ent/index.php | domain | 0601fc10951b… | 2018-05-03 |
| www.rhubarb2.com/ent/index.php | domain | 141b76bcd7a6… | 2018-05-08 |
| www.rhubarb2.com/telg/index.php | domain | 76fa36d35e0e… | 2016-01-27 |
| www.rhubarb3.com/get/index.php | domain | 041b4d2280ca… | 2016-11-26 |
| www.rhubarb3.com/ | domain | 309523ecd0c4… | 2018-05-08 |
| www.rhubarb3.com/ | domain | adc712518e21… | 2018-05-08 |
| www.rhubarb3.com/ | domain | d7da061b55d2… | 2017-09-24 |
| www.rhubarb3.com/ | domain | ef4d8bf8fec8… | 2018-05-08 |