AGP Picks
View all

FalconFeeds says pro-Houthi OilAlpha espionage group is active in 2026

11 hours ago
By AI, Created 12:25 UTC, Sep 29, 2026, AGP -

FalconFeeds.io says the pro-Houthi cyber-espionage group OilAlpha is still operating in 2026, with new Android spyware, live command-and-control servers and a WhatsApp lure posing as Saudi aid services. The findings matter because the group is targeting humanitarian workers, journalists and political figures tied to the Yemen conflict while those same people face detention and espionage charges in Yemen.

Why it matters: - OilAlpha is targeting people already at elevated risk in the Yemen conflict, including humanitarian staff, journalists and political figures. - FalconFeeds.io says the group's 2026 activity shows continuing operational capacity, not a dormant or disrupted campaign. - The report warns that the people OilAlpha surveils are the same people being detained by Houthi authorities. - As of February 2026, 73 UN staff were in Houthi detention, many on espionage charges. - FalconFeeds.io assesses with high confidence that OilAlpha was active as of August 2026 and is highly likely to remain active.

What happened: - FalconFeeds.io published new research on Sept. 29, 2026, on a pro-Houthi cyber-espionage group called OilAlpha. - The report says OilAlpha, first exposed in 2023, is still fully operational in 2026. - FalconFeeds.io and OSINT partner Sycek identified two previously unreported Android spyware samples. - The samples were built on the commodity SpyMax/SpyNote remote access trojan. - Analysts also identified live command-and-control infrastructure operating through at least August 2026. - The campaign included a KSrelief-themed WhatsApp lure that circulated among Yemeni users in May 2026.

The details: - Between December 2025 and February 2026, OilAlpha repointed its entire 2024 hostname set to a new server. - The first 2026 sample appeared two weeks later. - Six new hostnames followed in May 2026. - The most recent hostname was added on Aug. 18, 2026. - FalconFeeds.io says 47 of 51 historical OilAlpha C2 domains still resolve to two DigitalOcean-hosted servers assessed as actor-controlled. - Earlier assessments describing some domains as probable sinkholes were withdrawn. - The May 2026 lure was a roughly 13 MB ZIP-wrapped APK. - The lure spread through forwarded WhatsApp chains. - The lure impersonated Saudi Arabia's King Salman Humanitarian Aid and Relief Centre, known as KSrelief. - The lure used an Arabic-language "Inquiry" theme. - OilAlpha's malicious apps can provide GPS tracking, call interception, SMS exfiltration, and camera and microphone access. - Previous research by Recorded Future's Insikt Group identified the Norwegian Refugee Council, CARE International and KSrelief among impersonated organizations. - The United Nations and World Food Programme were also suspected in earlier research. - Operator-chosen package names from 2022 have given way to randomised builds. - The newer builds include anti-analysis checks and staged code loading. - APK sizes have grown from under 1 MB to 12.48 MB. - English-language visibility into OilAlpha ended in mid-2024. - The only public warning about the 2026 campaign appeared in Arabic-language Yemeni media and was surfaced through Sycek collection. - The report includes 28 platform-tracked OilAlpha C2 domains with per-indicator confidence scoring. - The report also includes the full 2026 indicator set, a MITRE ATT&CK Mobile mapping and detection guidance for security teams, NGO security managers and end users.

Between the lines: - FalconFeeds.io says public exposure has changed OilAlpha's tooling, not its mission. - After 2024 reporting, the group abandoned its phishing portal within weeks, rebuilt its infrastructure and returned with new builds and the same humanitarian lures. - The shift from fixed package names to randomised builds suggests more mature tradecraft. - The move to live C2 infrastructure suggests the group retained control over key assets rather than losing them to takedowns or sinkholes. - The information gap in English-language reporting may have allowed the 2026 campaign to stay under wider scrutiny.

What's next: - FalconFeeds.io expects OilAlpha to rotate tooling again after this report. - Security teams are urged to prioritize behavior-based detection over static indicators. - Recommended defenses include blocking or sinkholing OilAlpha hostnames and both C2 servers across staff mobile fleets. - Organizations should review DNS logs from December 2025 onward. - Managed devices should block sideloading and flag apps that request Accessibility or device-admin rights or hide their launcher icon. - Staff and beneficiaries should be told the organization does not distribute apps over WhatsApp, Telegram or SMS. - Organizations should enforce multi-factor authentication on organizational accounts. - Users should never open APK or ZIP files received over WhatsApp, even from a known contact.

The bottom line: - OilAlpha remains an active mobile espionage threat in 2026, with updated spyware, live infrastructure and the same humanitarian-focused lure set.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Non-Profits in the News

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Non-Profits in the News

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.