Hamas Hackers Sling Stealthy Spyware Across Egypt, Palestine
ID: 18dbab8c-810b-5ceb-b748-2b37b2f2297a
STIX ID: report--18dbab8c-810b-5ceb-b748-2b37b2f2297a
Feed Name: Dark Reading
Arid Viper (Hamas-linked APT) has been deploying AridSpy Android spyware since 2022 via trojanized messaging apps and malicious sites targeting users in Egypt and Palestine. New analysis shows AridSpy operates as a multistage trojan that downloads updated second-stage payloads from command-and-control servers and can exfiltrate location, contacts, call logs, SMS, photos/video thumbnails, clipboard and notifications, and can record audio and take pictures; multiple campaigns remain active.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
