GnatSpy is an Android spyware family associated with Arid Viper, also tracked as APT-C-23 and Desert Falcon. Public reporting places it in the group’s long-running mobile espionage toolkit alongside VAMP, FrozenCell, DesertScorpion, ViperRAT, and later SpyC23 variants. Trend Micro publicly reported GnatSpy in December 2017. Subsequent analysis cited substantial code and functionality overlap between newer SpyC23 samples and older Arid Viper Android malware families including GnatSpy, reinforcing attribution across the actor’s Android toolsets.
Based on the provided content, GnatSpy expands on VAMP’s functionality. In addition to VAMP-associated surveillance behavior such as call recording and theft of contacts and documents stored on the device, GnatSpy collects device-state information including battery usage, memory, storage, and SIM card status. Reporting also notes code linked to a 2017 GnatSpy sample being shared with later Arid Viper Android spyware.
The malware is tied to Arid Viper campaigns focused on cyber espionage in the Middle East. The broader actor has historically targeted military personnel, journalists, dissidents, Israeli soldiers, and Palestinian individuals and organizations, with more recent reporting highlighting interest in Arabic-speaking victims. Across Arid Viper’s Android operations, infection commonly relied on social engineering and weaponized applications masquerading as messaging, dating, networking, banking, or regional-themed apps, typically distributed outside official app stores. The content does not provide GnatSpy-specific indicators of compromise beyond its family association and the December 2017 public reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SentinelLABS compared these newer versions of SpyC23 to the earlier 2020 version, as well as several older Android spyware families associated with Arid Viper: GnatSpy, FrozenCell, and VAMP.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The main changes from earlier research centered primarily around code obfuscation being added by those developing this malware.
Retrieve photos from the camera roll ... Retrieve contacts ... Retrieve text messages ... Search for and return the path of files with a doc or PDF extension
The analyzed Arid Viper Android malware contained the following functionality: • Take screenshots or record video
Phenakite periodically recording audio and notifying C2 infrastructure... Similarly, Phenakite periodically uses the camera of a compromised device to take photos
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Older Arid Viper Android spyware family sharing code and upload functionality overlaps with newer SpyC23 variants; a 2017 sample shared the same upload functionality through a subclass JsDirService.
Android spyware extending VAMP with additional device profiling and status collection capabilities.
GnatSpy is identified as a newly discovered mobile malware family.
Named Android surveillanceware/tooling family attributed over time to APT-C-23/Arid Viper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.