AridSpy is a multi-layered Android malware distributed via 5 dedicated websites. Its presence has been detected in both Palestine and Egypt. It is a remotely controlled trojan for collecting user data, capable of exfiltrating content from the device
Researchers of ESET, a global European leader in the cybersecurity market, have identified five campaigns using Trojan-containing apps to target Android users. Most likely conducted by the APT Arid Viper group, these campaigns began in 2022 and three of them are still ongoing as of this press release. They use a multi-stage Android spyware, which ESET has named AridSpy, which downloads first- and second-level payloads from its command & control (C&C) server to allow it to evade detection. The malware is distributed through dedicated websites that mimic various messaging apps, a job posting app, and a Palestinian Civil Registry app. Typically, these are existing apps containing Trojans with the malicious code of AridSpy added. ESET Research has detected the AridSpy Trojan, which is remotely controlled and focuses on spying on user data, in Palestine and Egypt.
Arid Viper, also known as APT-C-23, Desert Falcons or Two-tailed Scorpion, is a cyberespionage group known for targeting Middle Eastern countries; the group has attracted attention over the years for its wide range of malware for Android, iOS and Windows platforms.
Three compromised apps distributed via spoofed websites are legitimate apps trojanized with the AridSpy spyware. These malicious apps have never been distributed via Google Play and can only be downloaded from third-party sites. To install these apps, the potential victim must enable Android's non-default option to install apps from unknown sources. Most spyware cases recorded in Palestine involved the malicious Palestinian Civil Registry app.
"To gain initial access to the device, threat actors try to convince the potential victim to install a fake, but working, app. Once the user clicks on the site's download button, myScript.js, hosted on the same server, is executed to generate the correct download path for the malicious file," he explains Lukáš Štefanko, ESET researcher who discovered AridSpy, describing how users get infected.
One of the campaigns included LapizaChat, a malicious Android messaging app with trojanized versions of StealthChat: Private Messaging bundled with AridSpy malicious code. ESET has identified two other campaigns that have started deploying AridSpy after LapizaChat, this time posing as messaging apps called NortirChat and ReblyChat. NortirChat is based on the legitimate messaging app Session, while ReblyChat is based on Voxer Walkie Talkie Messenger.
On the other hand, the Palestinian Civil Registry app is inspired by an app already available on Google Play. Based on investigations by ESET researchers, the malicious app available online is not a trojanized version of the app on Google Play, but uses the app's legitimate server to retrieve information. This means that Arid Viper took inspiration from the app's features, but created its own client layer that communicates with the legitimate server. Most likely, Arid Viper reverse engineered the legitimate Android app from Google Play and used its server to recover victims' data. The latest campaign identified by ESET distributes AridSpy as a job posting app.
AridSpy has a feature to avoid network detection, especially C&C communication. It can deactivate itself, as indicated in the AridSpy code. Data exfiltration is initiated either by receiving a command from the Firebase C&C server or by triggering a specific event. These events include changing Internet connectivity, installing or uninstalling the app, making or receiving a phone call, sending or receiving an SMS message, connecting or disconnecting the charger, or restarting the device.
If one of these events occurs, AridSpy begins collecting victim data and uploads it to the C&C exfiltration server. It can collect device location, contact lists, call logs, text messages, thumbnails of recorded photos and videos, recorded phone calls, recorded ambient audio, photos taken by the malware, WhatsApp databases containing the user's messages and contacts, bookmarks and search history from the default browser and Chrome, Samsung Browser and Firefox apps, if installed, files from external storage, Facebook Messenger and WhatsApp communications, and all notifications received, among other things.
For more technical information on AridSpy, see the blog post “Arid Viper poisons Android apps with AridSpy”.






