Phenakite is a custom iOS surveillance implant used by Arid Viper, also tracked as Desert Falcon and APT-C-23. Public reporting describes it as a short-lived and sparingly used iOS component that reflected the group’s expansion from its established Android tooling into iPhone targeting. Phenakite was embedded in a trojanized but functional chat application called Magic Smile, which used open-source RealtimeChat code for legitimate chat features. Victims were reportedly tricked into installing a mobile configuration profile and a device-specific signed app, allowing installation on non-jailbroken iPhones; after installation, the malware bundled the public Osiris jailbreak and Sock Port exploit to elevate privileges. Reporting states this supported jailbreaking 64-bit devices on iOS 11.2 to 11.3.1 with Osiris and extended support to iOS 10.0 to 12.2, with potential support for 12.4 and greater via Sock Port.
Documented capabilities include reading SMS messages; retrieving and exfiltrating contacts; collecting device metadata; retrieving photos; silently recording audio; taking photos with the device camera; collecting and exfiltrating WhatsApp media; and stealing files with selected extensions such as .pdf and .doc. Reporting also states it could retrieve content sent or received via the trojanized chat application and exfiltrate SQLite databases including ChatStorage.sqlite and sms.db. Additional reporting notes call-audio recording capability. Phenakite could also redirect users to phishing pages for iCloud and Facebook during the chat application sign-up flow to steal credentials.
Distribution and infrastructure details directly mentioned in reporting include discovery of samples first on a third-party mobile app development/distribution site and later on Arid Viper-controlled infrastructure, including use of zc.pgyer[.]com. Facebook reported a misconfigured Firebase instance associated with Phenakite showing 81 users at the time of analysis, though several were assessed to be adversary-controlled test or fake accounts. Some samples contained the team name "Brenda Braun" and team identifier "J22DGC9C5A." Apple reportedly revoked a developer certificate associated with the malware after notification, disrupting Arid Viper’s ability to distribute Phenakite and appearing to pause its iOS operations at that time.
Targeting described in the source material centers primarily on Palestinian individuals and organizations, including government officials, Fatah members, student groups, and security forces, within Arid Viper’s broader Middle East-focused espionage activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Arid Viper group has a long history of using mobile malware, including at least four Android spyware families and one short-lived iOS implant, Phenakite.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
If socially engineered, the victim must first be tricked into visiting an unofficial app store, third party app development site, or attacker controlled website hosting Phenakite.
Retrieve photos from the camera roll ... Retrieve contacts ... Retrieve text messages ... Search for and return the path of files with a doc or PDF extension
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A short-lived iOS implant associated with Arid Viper.
iOS spyware capable of recording calls, stealing WhatsApp media, photos, selected files, and redirecting victims to phishing pages to steal credentials.
Phenakite is identified as a named iOS malware sample/family.
Android malware that exfiltrates WhatsApp media, photos, and selected document types.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.