logo

Arid Viper poisons Android apps with AridSpy

ID: 7e5eca9c-b7fd-5983-bdc0-c64f398e104c

STIX ID: report--7e5eca9c-b7fd-5983-bdc0-c64f398e104c

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2024-06-13

Date Updated: 2026-05-01

...
...

ESET Research describes AridSpy, a maintained, multistage Android spyware family likely operated by the Arid Viper APT and distributed via dedicated websites and trojanized apps targeting users in Palestine and Egypt; the report provides a full technical analysis (staged payloads, Firebase C2 and separate exfiltration domains, accessibility abuse, keylogging, audio/video capture), IoCs (hashes, domains, IPs) and MITRE ATT&CK mappings to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.