Arid Viper is a long-running Arabic-speaking espionage group focused on the Israeli-Palestinian conflict, best known for prolific Windows and Android/iOS mobile spyware used against Palestinian, Israeli and wider Middle Eastern targets.
Arid Viper (MITRE APT-C-23, G1028) has been active since at least 2014 and is widely assessed by multiple vendors to align with Palestinian/Hamas interests, though no government has publicly confirmed attribution. It emerged with desktop malware such as Micropsia and Trojanized document lures, then pivoted heavily to mobile surveillance from 2017 onward.
The group's tradecraft centers on social engineering and romance/political lures delivering custom implants: Micropsia and PyMicropsia on Windows, and a large family of Android spyware including FrozenCell, GnatSpy, VAMP/SpyC23 and, more recently, AridSpy. Operators frequently stand up fake websites and Trojanized messaging or dating apps to distribute payloads.
MENA targeting is the group's defining trait: primary victims are Palestinian individuals and institutions, the Israeli military and government, and other regional entities in Egypt. ESET's 2024 AridSpy reporting documented Trojanized Palestinian Civil Registry and messaging apps (NortirChat, LapizaChat, ReblyChat) and a fake job app used to seed Android spyware. Cisco Talos separately reported continued politically themed phishing waves against Palestine.
Confidence in the overall activity cluster is high given years of corroborating vendor telemetry; attribution to a specific sponsor is medium and should be treated as an assessment. Note: the unrelated 'Dohdoor'/UAT-10027 campaign (2025-2026, U.S. education/healthcare) is NOT attributed to Arid Viper despite occasional conflation, and is excluded here.