Z A.I CyberSecurity Scoring
Z
Company Information
Website:https://zyper.com/
Employees number:7
Number of followers:2,782
NAICS:5112
Industry Type:Software Development
Homepage:zyper.com
Z Risk Score (AI oriented)
Between 550 and 599
ZSoftware Development
Updated:
30/03/2026
30/03/2026
557/1000
Very Poor
Ca
Z Global Score (TPRM)
xxxx
ZSoftware Development
Score locked

ZVery Poor
Current Score
557Ca (VERY POOR)
01000
4 incidents
-48.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
575
JULY 2026
571
JUNE 2026
569
MAY 2026
564
APRIL 2026
562
MARCH 2026
556
FEBRUARY 2026
580
Cyber Attack
02 Feb 2026 • Z
YouTube, Discord, Google, MediaFire, Telegram, Facebook and TikTok: Arsink RAT Targets Android Devices To Steal Data and Enable Remote Control
Arsink: Android Malware Exploits Cloud Tools for Large-Scale Data Theft
550
CRITICAL-30
MEDZYPTELMETTIKGOOYOU1770029110
Arsink: Android Malware Exploits Cloud Tools for Large-Scale Data Theft
A sophisticated Android remote access trojan (RAT) dubbed Arsink has been uncovered, leveraging free cloud services to steal sensitive data and remotely control infected devices. Security firm Zimperium tracked the malware over several months, identifying 1,216 unique APK files, 317 Firebase command-and-control (C2) servers, and 45,000 victim IP addresses across 143 countries.
### Distribution & Deception
Hackers distributed Arsink through Telegram channels, Discord posts, and MediaFire links, disguising it as modified or "pro" versions of popular apps from over 50 brands, including Google, YouTube, WhatsApp, Instagram, TikTok, and Facebook. Once installed, the malware requests excessive permissions, hides its icon, and operates covertly offering no legitimate functionality while harvesting data.
### Four Attack Variants
Zimperium identified four primary Arsink variants, each using different cloud-based exfiltration methods:
1. Firebase + Google Apps Script – Small data (e.g., device info) is sent to Firebase Realtime Database, while larger files (photos, audio) are uploaded via Google Apps Script to Google Drive.
2. Telegram Exfiltration – SMS messages, call logs, and device details are transmitted directly to a hacker-controlled Telegram bot.
3. Embedded Dropper – A secondary payload is hidden within the app, extracted and renamed (e.g., Ai_App.zip to App.apk) without requiring internet downloads, evading detection.
4. Hybrid Cloud Abuse – Combines Firebase, Google Drive, and Telegram for data theft and command execution.
### Data Theft & Remote Control
Arsink captures a full device snapshot, including:
- Device details (model, battery, location, Google account emails)
- SMS messages (including one-time passcodes)
- Call logs & contacts
- Microphone recordings (stored in cloud storage)
- Photos & files (listed for potential upload)
Attackers can remotely:
- Toggle the flashlight, vibrate the phone, or play sounds
- Change wallpaper, display messages, or speak text via text-to-speech
- Initiate calls, manage files (upload, delete, wipe external storage)
- Hide the app icon and maintain persistence via fake foreground notifications
### Global Impact & Victim Distribution
The malware has infected users across the Middle East, Asia, Africa, Europe, and the Americas, with the highest concentrations in:
- Egypt (13,000 infections)
- Indonesia (7,000)
- Iraq & Yemen (3,000 each)
- Türkiye (2,000)
- Pakistan & India (2,500 each)
- Bangladesh (1,600)
- Algeria & Morocco (1,000 each)
India’s high infection rate correlates with frequent Telegram-based APK distribution.
### Mitigation & Response
Zimperium collaborated with Google to dismantle malicious Firebase endpoints, Apps Scripts, and accounts. Google Play Protect now blocks known Arsink samples outside the Play Store. However, attackers rapidly adapt, making behavior-based detection critical for enterprises, particularly as the malware targets work-related credentials via SMS interception.
Arsink’s use of legitimate cloud services for C2 operations highlights the growing challenge of detecting malware that blends into normal traffic.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
579
DECEMBER 2025
576
NOVEMBER 2025
573
OCTOBER 2025
634
Breach
09 Oct 2025 • Z
Discord
Discord Third-Party Vendor Breach and Extortion Attempt (2025)
567
CRITICAL-67
ZYP2832128100925
Discord faced a major extortion attempt after cybercriminals breached its third-party customer service provider, Zendesk, compromising sensitive user data—including 2.1 million government-issued ID photos (driver’s licenses, passports) used for age verification. The attack, attributed to the Scattered Lapsus$ Hunters (SLH) group, exploited a compromised support agent account, granting unauthorized access for 58 hours. Stolen data also included usernames, email addresses, partial billing details (last four digits of credit cards), IP addresses, and customer service message logs. While attackers claimed 1.5TB of data (affecting 5.5M users), Discord disputed the scale, confirming ~70,000 users had ID photos exposed. The company refused ransom demands, terminated the vendor relationship, and launched forensic investigations with law enforcement. The breach underscores supply chain risks and the dangers of storing sensitive verification documents with third parties. The threat of public data leaks remains active, with potential long-term repercussions for affected users, including identity theft and fraud.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
633
MAY 2025
688
Breach
01 May 2025 • Z
Discord
Discord Third-Party Customer Service Data Breach
621
CRITICAL-67
ZYP3792137100525
Discord, a communication platform with over 200 million users, suffered a data breach via a third-party customer service provider. The hackers accessed a limited number of users' data, including those who had interacted with Discord’s Customer Support or Trust & Safety teams. Compromised information may include names, Discord usernames, emails, contact details, partial billing data (last four digits of credit cards, payment type, purchase history), IP addresses, messages with support agents, and a small number of government-ID images (e.g., driver’s licenses, passports) from age-verification appeals. While full credit card numbers, CVVs, passwords, authentication data, and general Discord activity/messages remained secure, the breach was conducted for financial extortion. Discord revoked the vendor’s access, launched an investigation, involved forensics experts, and engaged law enforcement to mitigate the incident.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2023
749
Breach
01 Sep 2023 • Z
Discord
Discord Third-Party Vendor Data Breach Exposes 70,000 Users' Government-Issued ID Photos
658
CRITICAL-91
ZYP0632206100925
Discord experienced a security breach via a third-party customer service vendor, exposing government-issued ID photos of approximately 70,000 users. The incident, discovered in late September 2023, targeted the platform’s age verification system used for reviewing user appeals. While Discord clarified this was not a direct breach of its core systems, the attackers accessed usernames, email addresses, contact details, partial billing information (last four digits of credit cards), IP addresses, and customer support messages. The hackers attempted extortion by demanding a ransom, with online claims suggesting they possessed more data than Discord acknowledged—though the company dismissed these as inflated. No full credit card numbers, passwords, or private Discord messages beyond support interactions were compromised. Discord revoked the vendor’s access, engaged forensic investigators, and collaborated with law enforcement. The breach highlights risks tied to third-party dependencies in handling sensitive user data, particularly in identity verification processes.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Z ??
What was Z's A.I Rankiteo Cyber Score in July 2026 ??
What was Z's A.I Rankiteo Cyber Score in June 2026 ??
What was Z's A.I Rankiteo Cyber Score in May 2026 ??
What was Z's A.I Rankiteo Cyber Score in April 2026 ??
What was Z's A.I Rankiteo Cyber Score in March 2026 ??
What was Z's A.I Rankiteo Cyber Score in February 2026 ??
What was Z's A.I Rankiteo Cyber Score in January 2026 ??
What was Z's A.I Rankiteo Cyber Score in December 2025 ??
What was Z's A.I Rankiteo Cyber Score in November 2025 ??
What was Z's A.I Rankiteo Cyber Score in October 2025 ??
What was Z's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Z's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Z ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Z's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?