ViperRAT is an Android surveillance malware family associated with Arid Viper, also known as APT-C-23 / Desert Falcon. The provided content identifies it as part of the evolving malware ecosystem attributed to that actor alongside VAMP, GnatSpy, FrozenCell, and DesertScorpion. Reported capabilities include collection of network configuration data such as phone number, SIM operator, and network operator; theft of SMS messages, call logs, contact lists, and system information including brand, manufacturer, and serial number; collection of device photos, PDF documents, Office documents, browser history, and browser bookmarks; and taking photos with the device camera. The broader reporting in the content ties APT-C-23 activity primarily to cyber-espionage targeting individuals and organizations in Palestine, including Palestinian government, security, Fatah-affiliated, and student targets. The content does not provide specific ViperRAT infection vectors or indicators of compromise beyond its association with APT-C-23 and the listed collection capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The ever-changing malware family attributed to APT-C-23 over the years includes VAMP, GnatSpy, FrozenCell, DesertScorpion, and ViperRAT.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The main changes from earlier research centered primarily around code obfuscation being added by those developing this malware.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Retrieve photos from the camera roll ... Retrieve contacts ... Retrieve text messages ... Search for and return the path of files with a doc or PDF extension
The analyzed Arid Viper Android malware contained the following functionality: • Take screenshots or record video
Phenakite periodically recording audio and notifying C2 infrastructure... Similarly, Phenakite periodically uses the camera of a compromised device to take photos
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android RAT capable of taking photos with the device camera.
Remote access trojan that steals photos, documents, and browser data from devices.
Remote access trojan that steals documents, photos, and browser data from devices.
Remote access trojan that steals documents, photos, and browser data from devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.