APT-C-23
Also reported as Arid Viper, Two-tailed Scorpion, Desert Falcons, Pinstripe Lightning, Scimitar and 13 other names. Linked to Palestine by two sources.
Reports per quarter
Techniques seen in the last two years
- T1418 2 reports reports only
- T1420 2 reports reports only
- T1426 2 reports reports only
- T1429 2 reports reports only
- T1512 2 reports reports only
- T1517 2 reports reports only
- T1532 2 reports reports only
- T1533 2 reports reports only
- T1398 1 report reports only
- T1406 1 report reports only
Show all 27 techniques Show fewer
- T1407 1 report reports only
- T1414 1 report reports only
- T1417.001 1 report reports only
- T1418.001 1 report reports only
- T1422 1 report in ATT&CK
- T1430 1 report reports only
- T1437 1 report reports only
- T1481.003 1 report reports only
- T1513 1 report reports only
- T1544 1 report reports only
- T1575 1 report reports only
- T1624.001 1 report reports only
- T1636.002 1 report reports only
- T1636.003 1 report reports only
- T1636.004 1 report reports only
- T1646 1 report reports only
- T1660 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-3906 KEV
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4114 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0097
Show all 77 CVEs Show fewer
- CVE-2015-0554
- CVE-2015-7248
- CVE-2015-7254
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-7921 KEV
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-8006
- CVE-2018-8373 KEV
- CVE-2018-8453 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-15126
- CVE-2019-19781 KEV ransomware
- CVE-2020-15892
- CVE-2020-15893
- CVE-2020-15894
- CVE-2020-15895
- CVE-2020-15896
- CVE-2020-3702
- CVE-2021-26084 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-27103 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20269 KEV ransomware
- CVE-2023-20273 KEV
- CVE-2023-22515 KEV ransomware
- CVE-2023-22518 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27351 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-40044 KEV ransomware
- CVE-2023-41763 KEV
- CVE-2023-42657
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-47246 KEV ransomware
- CVE-2023-4863 KEV
- CVE-2023-4911 KEV
- CVE-2023-4966 KEV ransomware
- CVE-2023-4967
- CVE-2023-50164
- CVE-2023-5217 KEV
- CVE-2023-6895
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
APT‑C‑23 group evolves its Android spyware | WeLiveSecurity
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor APT‑C‑23 group evolves its Android spyware | WeLiveSecurity
-
New GnatSpy Mobile Malware Family Discovered
The original link failed its last check. Original publisher Detailsfor New GnatSpy Mobile Malware Family Discovered
Show all 96 reports Show fewer
-
Operation Parliament - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Operation Parliament - Threat Group Cards: A Threat Actor Encyclopedia
-
Android APT spyware, targeting Middle East victims, enhances evasiveness
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Android APT spyware, targeting Middle East victims, enhances evasiveness
-
The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest
-
Hamas Android Malware On IDF Soldiers-This is How it Happened - Check Point Research
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Hamas Android Malware On IDF Soldiers-This is How it Happened - Check Point Research
-
Arid Viper poisons Android apps with AridSpy
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Arid Viper poisons Android apps with AridSpy
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor watchtower-2023-eoy-report-en
-
Gaza Cybergang Unified Front Targeting Hamas Opposition
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Gaza Cybergang Unified Front Targeting Hamas Opposition
-
Mantis- New Tooling Used in Attacks Against Palestinian Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mantis- New Tooling Used in Attacks Against Palestinian Targets
-
Escanor Malware Delivered In Weaponized Microsoft Office Documents
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Escanor Malware Delivered In Weaponized Microsoft Office Documents
-
Hamas-linked Hackers Targeting High-Ranking Israelis Using 'Catfish' Lures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hamas-linked Hackers Targeting High-Ranking Israelis Using 'Catfish' Lures
-
Operation Bearded Barbie- APT-C-23 Campaign Targeting Israeli Officials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Bearded Barbie- APT-C-23 Campaign Targeting Israeli Officials
-
What does Go-written malware look like- Here's a sample under the microscope
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What does Go-written malware look like- Here's a sample under the microscope
-
What is Arid Gopher- An Analysis of a New, Never-Before-Seen Malware Variant
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What is Arid Gopher- An Analysis of a New, Never-Before-Seen Malware Variant
-
Arid Viper APT targets Palestine with new wave of politically themed phishing attacks, malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Arid Viper APT targets Palestine with new wave of politically themed phishing attacks, malware
-
APT-C-23 Using New Variant Of Android Spyware To Target Users In The Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-23 Using New Variant Of Android Spyware To Target Users In The Middle East
-
Geopolitical nation-state threat actor overview June 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Geopolitical nation-state threat actor overview June 2021
-
Geopolitical nation-state threat actor overview May 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Geopolitical nation-state threat actor overview May 2021
-
Grab your own copy of Phenakite iOS malware today
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Grab your own copy of Phenakite iOS malware today
-
Taking Action Against Hackers in Palestine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taking Action Against Hackers in Palestine
-
Threat Group Uses Voice Changing Software in Espionage Attempt
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Uses Voice Changing Software in Espionage Attempt
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Uses Voice Changing Software in Espionage Attempt - Cado Security _ Cloud Native Digital Forensics
-
RemRAT- Android spyware that has been lurking in the Middle East for many years
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor RemRAT- Android spyware that has been lurking in the Middle East for many years
-
Mapping out AridViper Infrastructure Using Augury’s Malware Module – Team Cymru
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mapping out AridViper Infrastructure Using Augury’s Malware Module – Team Cymru
-
PyMICROPSIA- New Information-Stealing Trojan from AridViper
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PyMICROPSIA- New Information-Stealing Trojan from AridViper
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of the suspected two-tailed scorpion APT organization using CIA-funded information about Hamas as bait
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q32020
-
APT‑C‑23 group evolves its Android spyware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT‑C‑23 group evolves its Android spyware
-
APT‑C‑23 group evolves its Android spyware _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT‑C‑23 group evolves its Android spyware _ WeLiveSecurity
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-23.cn
-
Two-tailed_scorpion_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Two-tailed_scorpion_CN_version
-
Hamas Android Malware On IDF Soldiers-This is How it Happened
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hamas Android Malware On IDF Soldiers-This is How it Happened
-
New Cyber Espionage Campaigns Targeting Palestinians - Part 1- The Spark Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Cyber Espionage Campaigns Targeting Palestinians - Part 1- The Spark Campaign
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MICROPSIA (APT-C-23)
-
The Gaza cybergang and its SneakyPastes campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Gaza cybergang and its SneakyPastes campaign
-
Gaza Cybergang Group1 operation SneakyPastes
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gaza Cybergang Group1 operation SneakyPastes
-
CeidPageLock: A Chinese RootKit - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CeidPageLock: A Chinese RootKit - Check Point Research
-
New GnatSpy Mobile Malware Family Discovered
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New GnatSpy Mobile Malware Family Discovered
-
Cisco Talos Blog: Research Spotlight: Needles in a Haystack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco Talos Blog: Research Spotlight: Needles in a Haystack
-
RESEARCH SPOTLIGHT: NEEDLES IN A HAYSTACK
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor RESEARCH SPOTLIGHT: NEEDLES IN A HAYSTACK
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2015年中国高持续性威胁(APT)研究报告
-
Updated Blackmoon banking Trojan stays focused on South Korean banking customers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Updated Blackmoon banking Trojan stays focused on South Korean banking customers
-
Evolution of Cyber Threats in the Corporate Sector
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Evolution of Cyber Threats in the Corporate Sector
-
Operation Arid Viper Slithers Back into View
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Arid Viper Slithers Back into View
-
Arid Viper – Israel entities targeted by malware packaged with sex video
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Arid Viper – Israel entities targeted by malware packaged with sex video
-
Sexually Explicit Material Used as Lures in Recent Cyber Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sexually Explicit Material Used as Lures in Recent Cyber Attacks
-
The Desert Falcons Targeted Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Desert Falcons Targeted Attacks
-
The Desert Falcons targeted attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Desert Falcons targeted attacks
-
Operation Arid Viper: Bypassing the Iron Dome
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Arid Viper: Bypassing the Iron Dome
Newest first. Details opens the report in Explore.