×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET: Arid Viper Group Targets Middle East Again, Infecting Palestinian Apps with AridSpy Spyware

Customer Press Room

ESET: Arid Viper Group Targets Middle East Again, Infecting Palestinian Apps with AridSpy Spyware

by Grandangolo Communications / Monday, 01 July 2024 / Published in Eset

AridSpy is a multi-layered Android malware distributed via 5 dedicated websites. Its presence has been detected in both Palestine and Egypt. It is a remotely controlled trojan for collecting user data, capable of exfiltrating content from the device

Researchers of ESET, a global European leader in the cybersecurity market, have identified five campaigns using Trojan-containing apps to target Android users. Most likely conducted by the APT Arid Viper group, these campaigns began in 2022 and three of them are still ongoing as of this press release. They use a multi-stage Android spyware, which ESET has named AridSpy, which downloads first- and second-level payloads from its command & control (C&C) server to allow it to evade detection. The malware is distributed through dedicated websites that mimic various messaging apps, a job posting app, and a Palestinian Civil Registry app. Typically, these are existing apps containing Trojans with the malicious code of AridSpy added. ESET Research has detected the AridSpy Trojan, which is remotely controlled and focuses on spying on user data, in Palestine and Egypt.

Arid Viper, also known as APT-C-23, Desert Falcons or Two-tailed Scorpion, is a cyberespionage group known for targeting Middle Eastern countries; the group has attracted attention over the years for its wide range of malware for Android, iOS and Windows platforms.

Three compromised apps distributed via spoofed websites are legitimate apps trojanized with the AridSpy spyware. These malicious apps have never been distributed via Google Play and can only be downloaded from third-party sites. To install these apps, the potential victim must enable Android's non-default option to install apps from unknown sources. Most spyware cases recorded in Palestine involved the malicious Palestinian Civil Registry app.

"To gain initial access to the device, threat actors try to convince the potential victim to install a fake, but working, app. Once the user clicks on the site's download button, myScript.js, hosted on the same server, is executed to generate the correct download path for the malicious file," he explains Lukáš Štefanko, ESET researcher who discovered AridSpy, describing how users get infected.

One of the campaigns included LapizaChat, a malicious Android messaging app with trojanized versions of StealthChat: Private Messaging bundled with AridSpy malicious code. ESET has identified two other campaigns that have started deploying AridSpy after LapizaChat, this time posing as messaging apps called NortirChat and ReblyChat. NortirChat is based on the legitimate messaging app Session, while ReblyChat is based on Voxer Walkie Talkie Messenger.

On the other hand, the Palestinian Civil Registry app is inspired by an app already available on Google Play. Based on investigations by ESET researchers, the malicious app available online is not a trojanized version of the app on Google Play, but uses the app's legitimate server to retrieve information. This means that Arid Viper took inspiration from the app's features, but created its own client layer that communicates with the legitimate server. Most likely, Arid Viper reverse engineered the legitimate Android app from Google Play and used its server to recover victims' data. The latest campaign identified by ESET distributes AridSpy as a job posting app.

AridSpy has a feature to avoid network detection, especially C&C communication. It can deactivate itself, as indicated in the AridSpy code. Data exfiltration is initiated either by receiving a command from the Firebase C&C server or by triggering a specific event. These events include changing Internet connectivity, installing or uninstalling the app, making or receiving a phone call, sending or receiving an SMS message, connecting or disconnecting the charger, or restarting the device.

If one of these events occurs, AridSpy begins collecting victim data and uploads it to the C&C exfiltration server. It can collect device location, contact lists, call logs, text messages, thumbnails of recorded photos and videos, recorded phone calls, recorded ambient audio, photos taken by the malware, WhatsApp databases containing the user's messages and contacts, bookmarks and search history from the default browser and Chrome, Samsung Browser and Firefox apps, if installed, files from external storage, Facebook Messenger and WhatsApp communications, and all notifications received, among other things.

For more technical information on AridSpy, see the blog post “Arid Viper poisons Android apps with AridSpy”.

Tagged under: Arid Viper, Eset

About Grandangolo Communications

What you can read next

ESET Research discovers PromptSpy, the first Android threat to use generative AI
ESET Threat Report explains the attacks related to the Ukraine crisis and how the war has changed the threat landscape
ESET updates its consumer offering for advanced protection against ransomware and scams

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP