ZooPark

First seen
2015-06-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:54:50

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:ae country_code:sa country_code:eg country_code:ir

Context

ZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind ZooPark infect Android devices using several generations of malware we label from v1-v4, with v4 being the most recent version deployed in 2017.

Reports & references

  • Kaspersky — 85394 (report)

External references