◇ SIGN IN
← all actors
apt

OilAlpha

activemedium confidence
APT / State-sponsored
OilAlpha
Attribution
Suspected pro-Houthi threat cluster; infrastructure traced to Yemen's Houthi-controlled Public Telecommunication Corporation (PTC)
Origin
Yemen
First seen
2023
Last active
2024
Motivation
Espionage
Confidence
medium
MENA targeting
Yemen, broader Arabian Peninsula
Sectors
Humanitarian/NGO sector, aid organizations, media
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Yemen, broader Arabian Peninsula (Humanitarian/NGO sector, aid organizations, media sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

OilAlpha is a suspected pro-Houthi activity cluster in Yemen that uses Android spyware and social-engineering lures to target humanitarian, media, NGO and military entities across the Arabian Peninsula.

History

OilAlpha was first documented by Recorded Future in May 2023 as an espionage campaign targeting development, humanitarian, media and non-governmental organizations across the Arabian Peninsula. Analysts assess a pro-Houthi orientation, notably because command infrastructure has been traced to the Public Telecommunication Corporation (PTC), a Yemeni state entity under Houthi-aligned control.

Tradecraft is centered on mobile: operators distribute malicious Android APKs, frequently via WhatsApp, that impersonate legitimate organizations and carry commodity remote-access trojans such as SpyMax/SpyNote. The apps request intrusive permissions to steal credentials, messages, location and files. The group leans on social engineering and brand impersonation rather than sophisticated exploits.

In a June 2024 wave (reported by Recorded Future's Insikt Group), OilAlpha impersonated humanitarian bodies including CARE International, the Norwegian Refugee Council and the Saudi King Salman Humanitarian Aid and Relief Centre, likely to collect intelligence that could shape or control aid distribution in Yemen. Separate reporting noted spyware use against military personnel across the region.

MENA relevance is intrinsic: the actor is Yemen-based and focused on the Arabian Peninsula. Confidence in the activity is high; the pro-Houthi attribution is medium, resting largely on PTC infrastructure links and victimology rather than confirmed sponsorship. No confirmed 2025-2026 campaign has been published, so 'active' reflects recent-years persistence with a 2024 last-confirmed date.

Notable campaigns

2023
OilAlpha (initial disclosure)
Recorded Future exposed Android spyware and social-engineering targeting NGOs, media and development orgs across the Arabian Peninsula.
2024
Humanitarian-aid impersonation wave
Malicious apps posing as CARE International, NRC and the King Salman relief centre delivered SpyMax to Yemen aid organizations via WhatsApp.