Arid Viper is a Palestinian cyber-espionage threat actor active since at least the mid-2010s and widely tracked under aliases including APT-C-23, Desert Falcon, Two-tailed Scorpion, Mantis, Grey Karkadann, Big Bang APT, Renegade Jackal, Scimitar, TAG-63, and Pinstripe Lightning. The group is commonly assessed to operate from Palestine, with multiple reports placing it in Gaza or the Palestinian territories, and several assessments link it to Hamas or Hamas-aligned interests. Its dominant mission is intelligence collection against political, military, security, and civil targets in the Middle East. Arid Viper has repeatedly targeted Palestinian and Israeli victims, including government officials, members of the Fatah political party, student groups, security forces, activists, Palestinian organizations, and Israeli military, defense, law-enforcement, and emergency-services personnel. Broader victimology reported for the group includes government, military, financial, media, education, energy, and think-tank sectors. Campaigns are typically highly targeted and rely heavily on social engineering, including spear-phishing, politically themed decoy documents, fake social-media personas, and romance or messaging-themed lures. The actor maintains a multi-platform malware arsenal spanning Windows, Android, and iOS. On Windows, Arid Viper is strongly associated with the Micropsia malware family and related variants including PyMICROPSIA and the Go-based Arid Gopher, as well as campaign-specific tooling such as Barb(ie) and BarbWire. These implants support host reconnaissance, command execution, screenshot capture, audio recording, keylogging, credential theft, file collection, payload download, and exfiltration. The group has shown sustained malware development across Delphi, Python, Go, C++, and related tooling, and has repeatedly rewritten or repackaged implants to reduce detection and preserve operational resilience. On mobile platforms, Arid Viper has long specialized in Android spyware delivered through trojanized applications masquerading as chat, dating, update, VPN, or Telegram-themed software. Reported Android families and clusters associated with the actor include SpyC23, GnatSpy, FrozenCell, VAMP, VolatileVenom, and other custom backdoors. These implants commonly steal contacts, SMS messages, call logs, notifications, files, location data, device metadata, and messaging-app content; some variants can record audio, capture images, place calls, download additional modules, and abuse accessibility or device-administration features for surveillance and persistence. The group has also operated a custom iOS surveillanceware implant known as Phenakite, reflecting a rarer but notable capability to target Apple mobile devices. Operationally, Arid Viper frequently uses phishing sites and dedicated malware-hosting websites, often tailored to specific lure themes. It has used fake Facebook personas and catfishing to build rapport with targets, then shifted conversations to other messaging platforms to deliver malware. The actor commonly deploys decoy documents, startup-based persistence, registry-based persistence, staged payload delivery, and HTTP-based command-and-control, while some campaigns have also used reverse tunneling and modular second-stage execution. Multiple reports describe the group as adaptive rather than technically cutting-edge: it often reuses familiar tradecraft, but compensates with persistence, targeting discipline, and continuous malware iteration. Arid Viper is best characterized as a politically motivated Palestinian espionage actor focused on long-term surveillance and information theft in the Middle East, especially against Palestinian and Israeli political, governmental, military, and security-related targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
327 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Palestinian threat actor conducting geopolitically motivated spear-phishing in the Middle East.
Referenced as a group tied to infrastructure observed communicating with potentially vulnerable OpenSSL-exposed systems; described as conducting espionage on behalf of Hamas.
Cyber espionage group active since 2015 using Android and Windows malware and advanced social engineering to target journalists, human rights activists, and military groups.
Assessed as a likely operator behind a deceptive Android trojanized ‘Red Alert’ app campaign targeting people in Israel, using SMS lures impersonating Israel’s Home Front Command to drive APK installation and steal device data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.