Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ZooPark

Also known as: APT-C-38, Saber Lion, APT-C-38 (QiAnXin), SABER LION, TG-2884 (SCWX CTU)

Description

**Targets:** Egypt, Jordan, Morocco, Lebanon, Iran, Iraqi Kurdistan **Modus Operandi:** Android malware, Windows malware

TTP Summary

Android malware, Windows malware

Goals & Targeting

Targeted Countries / Regions

IR

AI Analysis

· 1 week ago

Executive Summary

ZooPark is a nation-state threat actor primarily involved in espionage activities. Known aliases include APT-C-38, Saber Lion, and TG-2884. The group targets Middle Eastern countries and sectors using Android and Windows malware. Their operations suggest moderate sophistication with a focus on intelligence gathering.

Goals & Targeting

ZooPark appears to target countries in the MENA region, particularly those involved in politics or security matters. The group's primary motivation is espionage, indicating a focus on gathering sensitive information for potential diplomatic or strategic advantage. Typical victims include government agencies, military personnel, or organizations with access to politically significant data.

Enhanced Description

ZooPark, also known as APT-C-38 or Saber Lion, is a nation-state actor suspected to be linked to espionage activities in the Middle East and North Africa (MENA) region. The group has been observed targeting countries such as Egypt, Jordan, Morocco, Lebanon, Iran, and Iraqi Kurdistan. ZooPark's primary modus operandi involves the development and deployment of Android and Windows malware for compromising targets. While their exact tools and techniques remain unclear due to limited public reporting, the group's activities align with state-sponsored espionage campaigns aimed at gathering sensitive political, military, or economic intelligence. The targeting of specific countries suggests a regional focus, possibly aligned with broader geopolitical objectives. Given the reliance on malware, ZooPark likely has moderate technical capabilities, though details about their exact infrastructure and long-term goals remain speculative.

Key Capabilities

  • Android malware
  • Windows malware
  • Espionage activities

MITRE ATT&CK Tactics

Reconnaissance
Exfiltration

Software / Tooling

Custom Android malware
Custom Windows malware

Campaigns & Victims

ZooPark's campaigns have been linked to targeting Middle Eastern countries, with a focus on intelligence gathering. While specific details about their campaign patterns are limited, the group appears to operate with moderate persistence, leveraging malware to compromise targets. Notable past operations include activities in Egypt and Jordan, though precise details remain underreported.

IOC Patterns

  • Android malware activity
  • Windows malware activity
  • Potential use of custom espionage tools

Recommended Actions

  • Implement advanced endpoint detection solutions to monitor for signs of Android or Windows malware.
  • Conduct regular updates and patching of operating systems to mitigate known vulnerabilities.
  • Enhance email security to prevent potential phishing attempts associated with ZooPark's modus operandi.

Suggested Tags

APT
espionage
Mideast/North_Africa

Confidence Assessment

Confidence in ZooPark's details is moderate due to limited available information. While the group's activity pattern and targeting are identified, specifics about their tools, techniques, and long-term goals remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
Mideast/North_Africa

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.