APT-C-23 Weaponized Israel’s ‘Red Alert’ App for Mobile Espionage
ID: 57c59694-0818-5128-84db-7283581004c7
STIX ID: report--57c59694-0818-5128-84db-7283581004c7
Feed Name: securityonline.info
Acronis TRU identified a calculated campaign delivering a trojanized version of the Red Alert Android app to Israeli users via SMS; the malicious app preserves alert functionality while performing background espionage (collecting SMS, contacts, location, device accounts, and installed apps) and continuously exfiltrating staged data to an attacker-controlled C2. Researchers link the activity to Arid Viper (APT-C-23) and note sophisticated techniques including certificate spoofing, runtime manipulation to bypass Android signing checks, and permission abuse; users are advised to install emergency apps only from official app stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
