TF-MAL-apk.zoopark
📛 Threat Title
Malware family: ZooPark
Description
ThreatFox malware family `apk.zoopark`. Printable name: ZooPark.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.zoopark
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.zoopark
IOC database
- Type
- domain
- Value
apk.zoopark- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.zoopark
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.zoopark
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybernews.com
The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.
-
web:ieeexplore.ieee.org
The evolution of IoT malware has ignited interest in the creation of malware family classification models. Nonetheless, these models encounter security concerns stemming from issues related to their interpretability and vulnerabilities exposed within the training pipeline. Recent research highlighted the limitations of learning-based malware classifiers, which are susceptible to backdoor ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the ZooPark malware family including references, samples and yara signatures.
-
web:media.kasperskycontenthub.com
ZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind ZooPark infect Android devices using several generations of malware we label from v1-v4, with v4 being the most recent version deployed in 2017. The preferred infection vector for ZooPark is waterhole attacks. We found several news websites that have been ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.kaspersky.com
Malware beasts and where to find them ZooPark Trojan spyware is used for targeted attacks — in other words, it's not sent out randomly to ensnare just anyone; it aims for a specific audience. As we said, the criminals behind ZooPark target those who are interested in specific topics — in this case, Middle Eastern politics.
-
web:www.mcafee.com
After attempting and failing to rebuild several English based conversations we have little confidence that the entire data set came from ZooPark . However, It does exemplify the real danger of sensitive conversations being collected by Zoopark and available for their operations.
-
web:www.ncsc.gov.uk
How to defend organisations against malware or ransomware attacks.
-
web:www.semanticscholar.org
A dynamic trigger generation method based on sample features, which is referred to as "BENIGN", is devised and used to contaminate and launch attacks on the model while also implementing a tailored training process to achieve specific attack objectives. The evolution of IoT malware has ignited interest in the creation of malware family classification models. Nonetheless, these models ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.