logo

APT-C-23 Weaponized Israel’s ‘Red Alert’ App for Mobile Espionage

ID: 57c59694-0818-5128-84db-7283581004c7

STIX ID: report--57c59694-0818-5128-84db-7283581004c7

Feed Name: securityonline.info

Threat Score
83/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

Acronis TRU identified a calculated campaign delivering a trojanized version of the Red Alert Android app to Israeli users via SMS; the malicious app preserves alert functionality while performing background espionage (collecting SMS, contacts, location, device accounts, and installed apps) and continuously exfiltrating staged data to an attacker-controlled C2. Researchers link the activity to Arid Viper (APT-C-23) and note sophisticated techniques including certificate spoofing, runtime manipulation to bypass Android signing checks, and permission abuse; users are advised to install emergency apps only from official app stores.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.