Also known as: Mantis, Arid Viper, Desert Falcon, TAG-63, Grey Karkadann, Big Bang APT, Two-tailed Scorpion, APT-C-23, Gaza, Golden Rat, Goldmouse, ATK80, NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar, Bearded Barbie, MuddyWater, Cozy Bear, Midnight Blizzard, tracked as, malicious actors, APT groups, hackers, Shin Bet
APT-C-23 is a threat group that has been active since at least 2014.(Citation: symantec_mantis) APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile spyware targeting Android and iOS devices since 2017.(Citation: welivesecurity_apt-c-23)
spear phishing
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APTC-C23, also known as Mantis or Arid Viper, is a sophisticated cyber espionage group targeting Middle Eastern organizations since at least 2014. They specialize in mobile spyware targeting Android and iOS devices, aiming to gather sensitive information through spear phishing campaigns.
Goals & Targeting
APTC-C23’s strategic objectives revolve around espionage, aiming to gather intelligence from targeted sectors in the Middle East. Their focus on以色列likely indicates geopolitical motivations, potentially linked to regional powers. The group targets both public and private sector entities, suggesting a broad mandate to collect information on various aspects of national infrastructure and diplomatic activities.
Enhanced Description
APTC-C23 has been active for over eight years, primarily focusing on the Middle East with a particular emphasis on Israeli military assets. The group's operations span multiple sectors including government, defense, energy, and financial services. APTC-C23 is known for its development of mobile spyware since 2017, indicating a shift towards modern attack vectors. Their use of spear phishing as a primary TTP suggests a focus on human exploitation to achieve initial access. The group's sustained activity and specific targeting of sensitive sectors imply a high level of organizational structure and potential state sponsorship.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APTC-C23 has conducted long-term campaigns, leveraging mobile spyware to target high-value individuals and organizations. Their operational tempo suggests continuous activity with periodic updates to their tools and techniques. Notable past operations include multiple waves of spear phishing attempts paired with mobile device infections.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in APTC-C23's existence and primary activities based on multiple sources. However, some details regarding their exact affiliations and full toolset remain unknown.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
50
Tools
0
Campaigns
40
IOCs
0
Observed Data
3
Tactics