Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
shared APT-C-23/Arid Viper cluster behavior (G1028 has no MITRE technique relationships); Android spyware exfiltrates files and media from the device (ESET)
shared APT-C-23/Arid Viper cluster behavior (G1028 has no MITRE technique relationships); mobile spyware captures camera photos/video (SentinelOne SpyC23)
Credentials from Password Stores: Credentials from Web Browsers
credential access
Vendor report: malware had the ability to "steal passwords stored on the system registry (Internet Explorer and live Messenger)", described as "Password stealing" in the DHS variant.
Vendor report: attackers used "special characters in Unicode to reverse the order of characters in a file name, hiding the dangerous file extension in the file name and placing a harmless-looking fake file extension near the end."
Vendor report: malicious files stored in system directories under names like "skype.exe," "MSN.exe," and "msnn.dll" to blend with legitimate applications.
Vendor report: backdoor collects a "complete list of all files (especially XLS, DOC, JPG and WAV)" from victim machines for operator review, and "Information on all the .doc and .xls files on the victim's hard disk or connected USB devices."
shared APT-C-23/Arid Viper cluster behavior (G1028 has no MITRE technique relationships); requires target to open trojanized document or install fake app (ESET)
Vendor report: "Attackers created authentic Facebook accounts and then interacted with chosen victims through common Facebook pages until they had gained their trust. Then they sent them Trojan files in the chat hidden as an image."
shared APT-C-23/Arid Viper cluster behavior (G1028 has no MITRE technique relationships); stands up fake websites to host lures and Trojanized apps (ESET)
Associated software
1 linked · 1 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 1
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside Arid Viper (APT-C-23 / Desert Falcon)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1036partialAdaptive Application Control IntegrationT1036.005partialAdaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantAdvanced Anti-Phishing T1566.002significantApp GovernanceT1566significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantDefender for Cloud AppsT1071minimalDefender for Cloud AppsT1119partialMicrosoft Defender for IdentityT1071
respond · 7 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1566.002significantIncident ResponseT1564minimalIncident ResponseT1566minimalQuarantine PoliciesT1036significantQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantQuarantine PoliciesT1566significant
Countermeasures · D3FEND
Defensive techniques that counter Arid Viper (APT-C-23 / Desert Falcon)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.