Also known as: APT-C-38, Saber Lion, APT-C-38 (QiAnXin), SABER LION, TG-2884 (SCWX CTU)
**Targets:** Egypt, Jordan, Morocco, Lebanon, Iran, Iraqi Kurdistan **Modus Operandi:** Android malware, Windows malware
Android malware, Windows malware
Targeted Countries / Regions
Executive Summary
ZooPark is a nation-state threat actor primarily involved in espionage activities. Known aliases include APT-C-38, Saber Lion, and TG-2884. The group targets Middle Eastern countries and sectors using Android and Windows malware. Their operations suggest moderate sophistication with a focus on intelligence gathering.
Goals & Targeting
ZooPark appears to target countries in the MENA region, particularly those involved in politics or security matters. The group's primary motivation is espionage, indicating a focus on gathering sensitive information for potential diplomatic or strategic advantage. Typical victims include government agencies, military personnel, or organizations with access to politically significant data.
Enhanced Description
ZooPark, also known as APT-C-38 or Saber Lion, is a nation-state actor suspected to be linked to espionage activities in the Middle East and North Africa (MENA) region. The group has been observed targeting countries such as Egypt, Jordan, Morocco, Lebanon, Iran, and Iraqi Kurdistan. ZooPark's primary modus operandi involves the development and deployment of Android and Windows malware for compromising targets. While their exact tools and techniques remain unclear due to limited public reporting, the group's activities align with state-sponsored espionage campaigns aimed at gathering sensitive political, military, or economic intelligence. The targeting of specific countries suggests a regional focus, possibly aligned with broader geopolitical objectives. Given the reliance on malware, ZooPark likely has moderate technical capabilities, though details about their exact infrastructure and long-term goals remain speculative.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
ZooPark's campaigns have been linked to targeting Middle Eastern countries, with a focus on intelligence gathering. While specific details about their campaign patterns are limited, the group appears to operate with moderate persistence, leveraging malware to compromise targets. Notable past operations include activities in Egypt and Jordan, though precise details remain underreported.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in ZooPark's details is moderate due to limited available information. While the group's activity pattern and targeting are identified, specifics about their tools, techniques, and long-term goals remain unclear.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics