C-23 is an Android-focused espionage threat actor active since at least 2017 and also tracked as GnatSpy, FrozenCell, and VAMP. The group has targeted individuals in the Middle East, particularly in the Palestinian Territories, using spyware delivered through socially engineered mobile applications masquerading as legitimate update or utility software. C-23’s operations emphasize covert surveillance, persistence, and defense evasion on Android devices. Its spyware has used intrusive permission requests and social engineering to obtain broad access to victim devices, including notification access, device administrator privileges, and monitoring of user interactions. The malware can alter its icon and displayed name to impersonate trusted applications, launch legitimate apps to reduce suspicion, suppress or dismiss security-related notifications, and maintain resilience by updating command-and-control settings after deployment. The spyware attributed to C-23 has supported extensive post-compromise collection and exfiltration, including SMS messages, contacts, call logs, files, screenshots, screen recordings, camera captures, ambient audio, notifications, and voice-call data including messaging-app calls. It has also received operator commands through cloud messaging infrastructure, indicating an actively managed surveillance capability. The actor’s tradecraft is consistent with targeted mobile espionage against specific persons rather than broad financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware campaign using trojanized update-themed apps to spy on targeted individuals, with newer variants adding resilience against manual removal and C2 takedowns.
Android spyware operations targeting individuals in the Middle East, particularly the Palestinian Territories, using malicious apps disguised as update utilities and employing social engineering, permission abuse, stealthy icon/name changes, Firebase-delivered commands, and resilient command-and-control updates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.