s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.spyc23

📛 Threat Title

Malware family: SpyC23

Category: SpyC23 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.spyc23`. Printable name: SpyC23.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Tool: SpyC23 ... Last change to this tool card: 28 June 2025 Download this tool card in JSON format

  • web:attack.mitre.org

    SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017. SpyC23 has been observed primarily targeting Android devices in the Middle East. [1] There are multiple close variants of SpyC23 , such as VAMP [2], GnatSpy [3], Desert Scorpion and FrozenCell, which add some additional functionality but are not significantly different from the original malware .

  • web:github.com

    In the same year, multiple analyses of APT-C-23's mobile malware were published. Compared to the versions documented in 2017, Android/ SpyC23 .A has extended spying functionality, including reading notifications from messaging apps, call recording and screen recording, and new stealth features, such as dismissing notifications from built-in ...

  • web:malpedia.caad.fkie.fraunhofer.de

    AridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a focus on Israel and Palestine. The group employs custom-developed mobile malware , including variants like AridSpy, GnatSpy, and Micropsia, often delivered through spear-phishing emails and deceptive applications. Their operations involve sophisticated social ...

  • web:rewterz.com

    Analysis Summary APT C-23 also known as AridViper and Desert Falcon is active in middle east region targeting different sectors with their malicious documents. The group's discovery came around March 2017 and their main target emerged as the Middle East. The group has previously faked an android app to deploy Android/ SpyC23 mainly for spying, including reading notifications from messaging ...

  • web:securitychris.com

    The cybersecurity landscape has been rocked by the discovery of a new malware campaign attributed to the Arid Viper threat group, known for its politically motivated cyber espionage activities. The latest wave of attacks, employing a sophisticated variant of the SpyC23 malware , has been targeting entities in the Middle East, particularly focusing on military personnel, journalists, and activists.

  • web:www.eset.com

    "A collaborative analysis showed that this malware was part of the APT-C-23 arsenal - a new, enhanced version of their mobile spyware," explains Lukáš Štefanko, the ESET researcher who analyzed Android/ SpyC23 .A. The spyware was found lurking behind seemingly legitimate apps in a fake Android app store.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.sentinelone.com

    Background The Arid Viper group has a long history of using mobile malware , including at least four Android spyware families and one short-lived iOS implant, Phenakite. The SpyC23 Android malware family has existed since at least 2019, though shared code between the Arid Viper spyware families dates back to 2017. It was first reported in 2020 by ESET in a campaign where the actor used a third ...

  • web:www.sophos.com

    Sophos, a global leader in next-generation cybersecurity, has published, "Android APT Spyware, Targeting Middle East Victims, Enhances Evasiveness," detailing new variants of Android spyware linked to C-23, an advanced persistent threat (APT) adversary that has been active in the Middle East since 2017. The new variants are enhanced for stealth and persistence.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.