◇ SIGN IN
← all actors
apt

Arid Viper (APT-C-23 / Desert Falcon)

activehigh confidence
APT / State-sponsored
APT-C-23Desert FalconMantisGrey KarkadannTwo-tailed ScorpionTAG-63Big Bang APT
Attribution
Suspected Hamas-aligned / Palestinian-nexus cyber-espionage actor (attribution assessed, not confirmed by a government)
Origin
Palestinian Territories (suspected)
First seen
2014
Last active
2025
Motivation
Espionage
Confidence
high
MENA targeting
Palestine, Egypt, Israel
Sectors
Government, mobile/individual targets, civil registry services
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, high confidence, documented targeting Palestine, Egypt, Israel (Government, mobile/individual targets, civil registry services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Arid Viper is a long-running Arabic-speaking espionage group focused on the Israeli-Palestinian conflict, best known for prolific Windows and Android/iOS mobile spyware used against Palestinian, Israeli and wider Middle Eastern targets.

History

Arid Viper (MITRE APT-C-23, G1028) has been active since at least 2014 and is widely assessed by multiple vendors to align with Palestinian/Hamas interests, though no government has publicly confirmed attribution. It emerged with desktop malware such as Micropsia and Trojanized document lures, then pivoted heavily to mobile surveillance from 2017 onward.

The group's tradecraft centers on social engineering and romance/political lures delivering custom implants: Micropsia and PyMicropsia on Windows, and a large family of Android spyware including FrozenCell, GnatSpy, VAMP/SpyC23 and, more recently, AridSpy. Operators frequently stand up fake websites and Trojanized messaging or dating apps to distribute payloads.

MENA targeting is the group's defining trait: primary victims are Palestinian individuals and institutions, the Israeli military and government, and other regional entities in Egypt. ESET's 2024 AridSpy reporting documented Trojanized Palestinian Civil Registry and messaging apps (NortirChat, LapizaChat, ReblyChat) and a fake job app used to seed Android spyware. Cisco Talos separately reported continued politically themed phishing waves against Palestine.

Confidence in the overall activity cluster is high given years of corroborating vendor telemetry; attribution to a specific sponsor is medium and should be treated as an assessment. Note: the unrelated 'Dohdoor'/UAT-10027 campaign (2025-2026, U.S. education/healthcare) is NOT attributed to Arid Viper despite occasional conflation, and is excluded here.

Notable campaigns

2017
SpyC23 / VAMP Android surveillance
Sustained Android spyware operations against Palestinian and Israeli mobile users using Trojanized messaging and news apps.
2022
Israeli military mobile targeting
Fake dating and social apps used to lure Israeli soldiers into installing surveillance implants.
2024
AridSpy
ESET documented Trojanized Palestinian Civil Registry and chat apps distributing the multi-stage AridSpy Android spyware.
2025
Palestine phishing wave
Cisco Talos reported new politically themed spear-phishing delivering updated Windows and mobile malware against Palestinian targets.