Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors APT-C-23

Also known as: Mantis, Arid Viper, Desert Falcon, TAG-63, Grey Karkadann, Big Bang APT, Two-tailed Scorpion, APT-C-23, Gaza, Golden Rat, Goldmouse, ATK80, NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar, Bearded Barbie, MuddyWater, Cozy Bear, Midnight Blizzard, tracked as, malicious actors, APT groups, hackers, Shin Bet

Description

APT-C-23 is a threat group that has been active since at least 2014.(Citation: symantec_mantis) APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile spyware targeting Android and iOS devices since 2017.(Citation: welivesecurity_apt-c-23)

TTP Summary

spear phishing

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Financial services
Education
Telecommunications
Transportation
Media
Non profit
Legal services
Healthcare
Critical infrastructure
Manufacturing

Targeted Countries / Regions

IL
CN
EG
VN
KR
RU

AI Analysis

· 1 week ago

Executive Summary

APTC-C23, also known as Mantis or Arid Viper, is a sophisticated cyber espionage group targeting Middle Eastern organizations since at least 2014. They specialize in mobile spyware targeting Android and iOS devices, aiming to gather sensitive information through spear phishing campaigns.

Goals & Targeting

APTC-C23’s strategic objectives revolve around espionage, aiming to gather intelligence from targeted sectors in the Middle East. Their focus on以色列likely indicates geopolitical motivations, potentially linked to regional powers. The group targets both public and private sector entities, suggesting a broad mandate to collect information on various aspects of national infrastructure and diplomatic activities.

Enhanced Description

APTC-C23 has been active for over eight years, primarily focusing on the Middle East with a particular emphasis on Israeli military assets. The group's operations span multiple sectors including government, defense, energy, and financial services. APTC-C23 is known for its development of mobile spyware since 2017, indicating a shift towards modern attack vectors. Their use of spear phishing as a primary TTP suggests a focus on human exploitation to achieve initial access. The group's sustained activity and specific targeting of sensitive sectors imply a high level of organizational structure and potential state sponsorship.

Key Capabilities

  • Mobile spyware targeting Android and iOS devices
  • Spear phishing campaigns
  • Custom malware development

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1566
T1078
T1215

Software / Tooling

Micropsia
Mobile Spyware

Campaigns & Victims

APTC-C23 has conducted long-term campaigns, leveraging mobile spyware to target high-value individuals and organizations. Their operational tempo suggests continuous activity with periodic updates to their tools and techniques. Notable past operations include multiple waves of spear phishing attempts paired with mobile device infections.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Command-and-Control (C2) communication via mobile devices
  • Presence of specific mobile malware signatures

Recommended Actions

  • Enhance email filtering and employee training to mitigate spear phishing
  • Implement robust mobile device security solutions
  • Monitor for unusual network activity indicative of C2 communications

Suggested Tags

APT
espionage
mobile恶意软件
Middle East focused

Confidence Assessment

High confidence in APTC-C23's existence and primary activities based on multiple sources. However, some details regarding their exact affiliations and full toolset remain unknown.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 8 Domain 2 SHA-1 Hash 2 Filename 7 URL 1

References

  1. fb_arid_viper — Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024.
  2. sentinelone_israel_hamas_war — Hegel, T., Milenkoski, A. (2023, October 24). The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest. Retrieved March 4, 2024.
  3. checkpoint_interactive_map_apt-c-23 — Kayal, A. (2018, August 26). Interactive Mapping of APT-C-23. Retrieved March 4, 2024.
  4. welivesecurity_apt-c-23 — Stefanko, L. (2020, September 30). APT‑C‑23 group evolves its Android spyware. Retrieved March 4, 2024.
  5. symantec_mantis — Symantec Threat Hunter Team. (2023, April 4). Mantis: New Tooling Used in Attacks Against Palestinian Targets. Retrieved March 4, 2024.
  6. attack.mitre.org — Cited by web research for: T1660
  7. www.welivesecurity.com — Cited by web research for: T1418
  8. www.welivesecurity.com — Cited by web research for: T1444
  9. attack.mitre.org — Cited by web research for: T1583
  10. www.cybereason.com — Cited by web research for: Payload
  11. apt.etda.or.th — Cited by web research for: vamp

Intel Summary

40

Techniques

50

Tools

0

Campaigns

40

IOCs

0

Observed Data

3

Tactics

Tags

APT
espionage
mobile恶意软件
Middle East focused

Details

MITRE ID
G1028
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
S
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--8332952e-b86b-486b-acc3-1c2a85d39394
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.