Hackers Targeting Human Rights Activists in Morocco and Western Sahara

Teilen:

Human rights activists in Morocco and the Western Sahara region are the targets of a new threat actor that leverages phishing attacks to trick victims into installing bogus Android apps and serve credential harvesting pages for Windows users.

Cisco Talos is tracking the activity cluster under the name Starry Addax, describing it as primarily singling out activists associated with the Sahrawi Arab Democratic Republic (SADR).

Starry Addax’s infrastructure – ondroid[.]site and ondroid[.]store – is designed to target both Android and Windows users, with the latter involving fake websites masquerading as login pages for popular social media websites.

In light of active investigation into the campaign, Talos said it cannot publicly disclose which websites are being targeted with credential harvesting attacks.

“However, the threat actors are establishing their own infrastructure and hosting credential harvesting pages such as fake login pages for media and email services popular throughout the globe,” the company told The Hacker News.

The adversary, believed to be active since January 2024, is known to send spear-phishing emails to targets, urging recipients to install Sahara Press Service’s mobile app or a relevant decoy related to the region.

Depending on the operating system from where the request is originating from, the target is either served a malicious APK that impersonates the Sahara Press Service or redirected to a social media login page to harvest their credentials.

Starry Addax Hackers

The novel Android malware, dubbed FlexStarling, is versatile and equipped to deliver additional malware components and steal sensitive information from infected devices.

Once installed, it requests the victim to grant it extensive permissions that allow the malware to perform nefarious actions, including fetching commands to be executed from a Firebase-based command-and-control (C2), a sign that the threat actor is looking to fly under the radar.

“Campaigns like this that target high-value individuals usually intend to sit quietly on the device for an extended period,” Talos said.

“All components from the malware to the operating infrastructure seem to be bespoke/custom-made for this specific campaign indicating a heavy focus on stealth and conducting activities under the radar.”

The development comes amid the emergence of a new commercial Android remote access trojan (RAT) known as Oxycorat that’s being offered for sale with diverse information gathering capabilities.

The latest findings mark an interesting twist in that Starry Addax has taken pains to build its own arsenal of tools and infrastructure to target human rights activists as opposed to relying on commodity malware or commercially available spyware.

“The attacks are still in nascent stages, operationally. However, the supporting infrastructure and malware, FlexStarling, has been deemed mature enough by Starry Addax to start targeting human rights activists in North Africa,” Talos added.

“The timeline of events including establishing drop points, C2s and building malware since early January 2024 indicates that Starry Addax is rapidly setting up infrastructure to target high value individuals and will continue to gain momentum.”

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:36 pm, Juni 24, 2025
Wetter-Symbol 23°C
L: 21° | H: 24°
wenige Wolken
Luftfeuchtigkeit: 68 %
Druck: 1011 mb
Wind: 11 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 23%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 9 mph 69 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 29°°C 0 mm 0% 10 mph 82 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 15 mph 79 % 1018 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 14 mph 65 % 1022 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 29°°C 0 mm 0% 11 mph 80 % 1024 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 23°°C 0 mm 0% 9 mph 69 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 21°°C 0 mm 0% 8 mph 72 % 1012 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 7 mph 81 % 1012 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 7 mph 82 % 1012 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
24° | 24°°C 0 mm 0% 6 mph 57 % 1013 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 38 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
29° | 29°°C 0 mm 0% 10 mph 36 % 1010 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 39 % 1009 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,940.39
2.62%
Ethereum(ETH)
€2,097.36
5.85%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.90
7.23%
Solana(SOL)
€123.80
3.47%
USDC(USDC)
€0.86
0.01%
Dogecoin(DOGE)
€0.141478
4.68%
Shiba Inu(SHIB)
€0.000010
4.24%
Pepe(PEPE)
€0.000009
6.89%
Nach oben scrollen