Uptime Hamster: 10d 11h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ZooPark

ZooPark

0 incidentes 0 paises 0 sectores apt IR Ultimo: -
Aliases: APT-C-38, Saber Lion, vinculación con países como Egipto, Jordania, Marruecos, Líbano, Irán, el Kurdistan iraquí, dominios relacionados con análisis de amenazas, otros relacionados con países como Egipto, Jordon
Ver en IntelTracker → APTTrail →
ZooPark is an Iranian state-backed cyber-espionage group that emerged in June 2015, primarily targeting Android mobile devices across the Middle East. Its core motivation is politically driven intelligence gathering, aiming to surveil individuals and organizations. The group is characterized by the continuous evolution of its custom Android spyware, progressing through four distinct versions from a basic data-stealer to a highly sophisticated surveillance tool, potentially integrating commercially available spyware components in its later stages. ZooPark gained initial access through compromised news websites and malicious links shared on Telegram, often using politically charged lures to entice victims. The group's sustained focus on mobile platforms and its iterative development of sophisticated spyware for specific Middle Eastern targets set it apart from other threat actors, which are sometimes broadly labeled 'APT-C-23' or 'Domestic Kitten' but are distinct operations.

Aliases del actor

APT-C-38Saber Lionvinculación con países como EgiptoJordaniaMarruecosLíbanoIránel Kurdistan iraquídominios relacionados con análisis de amenazasotros relacionados con países como EgiptoJordon

Actores similares

apt-desertfalconactor · 1apt-stealthfalconactor · 1apt-glassesactor · 1Stealth Falconapt · 1Contagious Interviewapt · 1Confuciusapt · 1Desert Falconsapt · 0Conquerors Electronic Armyapt · 0Operation DRBControlapt · 0Confuciousapt · 0
Motivacion