ViperRAT is an Android surveillance malware family associated with the threat actor APT-C-23, also known as Arid Viper or Desert Falcon. It has been used in targeted espionage operations, including activity aimed at members of the Israeli Defense Forces, and is part of a broader cluster of evolving mobile tooling linked to that actor, alongside families such as VAMP, FrozenCell, DesertScorpion, and GnatSpy.
ViperRAT is designed for covert collection of sensitive data from compromised Android devices. Documented capabilities include harvesting SMS messages, contact lists, call logs, device photos, PDF and Office documents, browser history, browser bookmarks, system metadata such as brand, manufacturer, and serial number, and network or subscriber-related information including phone number and mobile operator details. It also supports use of the device camera to take photos, indicating a surveillance role beyond simple data theft.
The malware has used masquerading as a defense-evasion and social-engineering tactic. Its second stage has been observed posing as benign update-themed applications, including messaging-app and system-update lures, to reduce user suspicion and facilitate continued operation on infected devices. This behavior aligns with APT-C-23’s broader reliance on trojanized Android applications and impersonation of legitimate software in Middle East-focused espionage campaigns.
Based on the observed functionality, ViperRAT is best characterized as Android spyware or surveillanceware focused on victim monitoring, device profiling, and exfiltration of personal and operationally relevant data from targeted users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The ever-changing malware family attributed to APT-C-23 over the years includes VAMP, GnatSpy, FrozenCell, DesertScorpion, and ViperRAT.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The main changes from earlier research centered primarily around code obfuscation being added by those developing this malware.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
The analyzed Arid Viper Android malware contained the following functionality: • Take screenshots or record video
Phenakite periodically recording audio and notifying C2 infrastructure... Similarly, Phenakite periodically uses the camera of a compromised device to take photos
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile RAT/spyware family mentioned as another targeted surveillance example.
Android RAT capable of taking photos with the device camera.
Mobile RAT capable of collecting SMS messages.
Remote access trojan that steals documents, photos, and browser data from devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.