FrozenCell is an Android spyware family associated with the Arid Viper threat actor, also known as APT-C-23 and Desert Falcon. Reporting cited in the content links FrozenCell to Arid Viper’s long-running mobile espionage activity and notes that later Arid Viper Android tooling, including newer SpyC23 variants, shares substantial similarities with malware previously reported as FrozenCell and VAMP. The malware is part of Arid Viper’s broader surveillance toolkit used in campaigns targeting victims in the Middle East, with reporting specifically highlighting Palestinian individuals and organizations and, more broadly, military personnel, journalists, dissidents, government officials, security forces, Fatah members, and student groups. High-confidence capabilities explicitly attributed to FrozenCell in the content include collecting phone metadata such as cell location, mobile country code (MCC), and mobile network code (MNC); gathering device manufacturer, model, and serial number; reading SMS messages for exfiltration; and retrieving device images for exfiltration. The content also notes code and logging overlaps between newer SpyC23 components and older Arid Viper malware families including FrozenCell, reinforcing attribution to the same actor and indicating shared Android surveillance functionality across the toolset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SentinelLABS compared these newer versions of SpyC23 to the earlier 2020 version, as well as several older Android spyware families associated with Arid Viper: GnatSpy, FrozenCell, and VAMP.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The main changes from earlier research centered primarily around code obfuscation being added by those developing this malware.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Retrieve photos from the camera roll ... Retrieve contacts ... Retrieve text messages ... Search for and return the path of files with a doc or PDF extension
The analyzed Arid Viper Android malware contained the following functionality: • Take screenshots or record video
Phenakite periodically recording audio and notifying C2 infrastructure... Similarly, Phenakite periodically uses the camera of a compromised device to take photos
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older Arid Viper Android spyware family whose audio recording code and status logging strings overlap with newer SpyC23 samples.
Android malware that retrieves device images for exfiltration.
Malware that retrieves device images for exfiltration.
Malware that retrieves device images for exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.