APT-C-23
Malware family · 2 sample(s) · 4 indicator record(s) · 2 signing certificate(s)
About APT-C-23
Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| mediauploader.info | domain | e14f99608a8d… | 2018-06-10 |
| upload101.net/android/domains | domain | ca87cc9898af… | 2019-08-29 |
| upload101.net/android/domains | domain | e14f99608a8d… | 2018-06-10 |
| upload999.info | domain | ca87cc9898af… | 2019-08-29 |