Arid Viper Launches Mobile Espionage Campaign with AridSpy Malware
ID: 3d98ad1f-3a07-5c38-9f69-d6727352ff6f
STIX ID: report--3d98ad1f-3a07-5c38-9f69-d6727352ff6f
Feed Name: The Hacker News
ESET attributes a multi-stage Android spyware campaign to Arid Viper (APT-C-23) that uses trojanized or imitation apps distributed from fake websites to install AridSpy; the malware downloads additional payloads from C2 (including Firebase), harvests device data, can exfiltrate based on commands or events, and even take front-camera photos. Campaigns have targeted users in Palestine and Egypt since 2022, with multiple active waves and distribution vectors including apps impersonating messaging services, a Palestinian Civil Registry app, and a job-opportunity app.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
