OilAlpha is a suspected pro-Houthi activity cluster in Yemen that uses Android spyware and social-engineering lures to target humanitarian, media, NGO and military entities across the Arabian Peninsula.
OilAlpha was first documented by Recorded Future in May 2023 as an espionage campaign targeting development, humanitarian, media and non-governmental organizations across the Arabian Peninsula. Analysts assess a pro-Houthi orientation, notably because command infrastructure has been traced to the Public Telecommunication Corporation (PTC), a Yemeni state entity under Houthi-aligned control.
Tradecraft is centered on mobile: operators distribute malicious Android APKs, frequently via WhatsApp, that impersonate legitimate organizations and carry commodity remote-access trojans such as SpyMax/SpyNote. The apps request intrusive permissions to steal credentials, messages, location and files. The group leans on social engineering and brand impersonation rather than sophisticated exploits.
In a June 2024 wave (reported by Recorded Future's Insikt Group), OilAlpha impersonated humanitarian bodies including CARE International, the Norwegian Refugee Council and the Saudi King Salman Humanitarian Aid and Relief Centre, likely to collect intelligence that could shape or control aid distribution in Yemen. Separate reporting noted spyware use against military personnel across the region.
MENA relevance is intrinsic: the actor is Yemen-based and focused on the Arabian Peninsula. Confidence in the activity is high; the pro-Houthi attribution is medium, resting largely on PTC infrastructure links and victimology rather than confirmed sponsorship. No confirmed 2025-2026 campaign has been published, so 'active' reflects recent-years persistence with a 2024 last-confirmed date.