ZooPark

Malware family · 10 sample(s) · 10 indicator record(s) · 4 signing certificate(s) · Active 2016-01-27 → 2018-09-11 (experimental)

About ZooPark

ZooPark is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the Middle East (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.

Indicators

IndicatorTypeSampleFirst seen
androidupdaters.com domain 91659d5f35a8… 2017-04-08
androidupdaters.com domain f1ab53d9728d… 2018-09-11
entekhab10.xp3.biz/ent/index.php domain 0601fc10951b… 2018-05-03
www.rhubarb2.com/ent/index.php domain 141b76bcd7a6… 2018-05-08
www.rhubarb2.com/telg/index.php domain 76fa36d35e0e… 2016-01-27
www.rhubarb3.com/get/index.php domain 041b4d2280ca… 2016-11-26
www.rhubarb3.com/ domain 309523ecd0c4… 2018-05-08
www.rhubarb3.com/ domain adc712518e21… 2018-05-08
www.rhubarb3.com/ domain d7da061b55d2… 2017-09-24
www.rhubarb3.com/ domain ef4d8bf8fec8… 2018-05-08