APT-C-23

Malware family · 2 sample(s) · 4 indicator record(s) · 2 signing certificate(s)

About APT-C-23

Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.

Indicators

IndicatorTypeSampleFirst seen
mediauploader.info domain e14f99608a8d… 2018-06-10
upload101.net/android/domains domain ca87cc9898af… 2019-08-29
upload101.net/android/domains domain e14f99608a8d… 2018-06-10
upload999.info domain ca87cc9898af… 2019-08-29