logo

Arid Viper Launches Mobile Espionage Campaign with AridSpy Malware

ID: 3d98ad1f-3a07-5c38-9f69-d6727352ff6f

STIX ID: report--3d98ad1f-3a07-5c38-9f69-d6727352ff6f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-06-13

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

ESET attributes a multi-stage Android spyware campaign to Arid Viper (APT-C-23) that uses trojanized or imitation apps distributed from fake websites to install AridSpy; the malware downloads additional payloads from C2 (including Firebase), harvests device data, can exfiltrate based on commands or events, and even take front-camera photos. Campaigns have targeted users in Palestine and Egypt since 2022, with multiple active waves and distribution vectors including apps impersonating messaging services, a Palestinian Civil Registry app, and a job-opportunity app.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.