SpyC23 is an Android spyware family publicly reported by ESET in 2020 and assessed in later reporting as part of the mobile espionage toolkit used by Arid Viper, also tracked as APT-C-23 and the Gaza Cybergang. Reporting cited in the content links recent SpyC23 activity in 2022 and 2023 to Arid Viper, an espionage-focused threat actor aligned with Hamas interests, with targeting focused on the Middle East and a notable emphasis on Arabic-speaking victims. Historical targeting associated with the actor includes military personnel, journalists, dissidents, Israeli officials, Palestinian targets, and IDF soldiers.
SpyC23 has been distributed via weaponized Android applications masquerading as legitimate apps, including Telegram-themed apps, Android update-themed apps, and a dating-themed app called Skipped Messenger. The malware relies on social-engineering lures tied to messaging and romance themes to induce installation.
Capabilities directly described in the content include sending SMS messages; reading and exfiltrating SMS messages; exfiltrating the victim device’s contact list; exfiltrating the call log; and collecting and exfiltrating files with specific extensions such as .pdf and .doc. Additional reporting in the content states that newer variants request extensive permissions enabling surveillance functions including location access, call monitoring and recording, microphone recording, storage access, contact access, account enumeration, notification reading, silent file downloads, and network state modification. The CallRecService component and libcallrecfix.so are specifically associated with call recording functionality.
For command and control, SpyC23 can communicate over HTTPS and Firebase Cloud Messaging (FCM). Recent samples described in the content also used infrastructure consistent with Arid Viper naming conventions, with identified C2 domains including luis-dubuque.in, danny-cartwright.firm.in, and conner-margie.com.
The content also notes anti-analysis and evasion features in newer SpyC23 samples, including obfuscated code, anti-decompilation measures, and anti-virtualization techniques. Researchers identified substantial code, package, class, and functionality overlaps between SpyC23 and other Arid Viper Android malware families including GnatSpy, FrozenCell, and VAMP, reinforcing attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Through 2022 and 2023, the actor has distributed SpyC23, an Android spyware family, through weaponized apps posing as Telegram or as a dating app called Skipped.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The developer employed anti-decompilation and anti-virtualization techniques to complicate analysis. Each of these APKs contains application code that is obfuscated.
The application permissions give a high degree of control over the device, including: Read & Write to storage
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
DEFENSOR ID has used Firebase Cloud Messaging for C2; Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging; Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions.
Brodie contains a method named isProbablyArabic... Panda imports methods from the OKhttp library to craft HTTP requests.
DEFENSOR ID has used Firebase Cloud Messaging for C2. Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging. Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions. SpyC23 can communicate with the Command and Control server using HTTPS and Firebase Cloud Messaging (FCM). Trojan-SMS.AndroidOS.Agent.ao uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.FakeInst.a uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.OpFake.a uses Google Cloud Messaging (GCM) for command and control.
SpyNote RAT can copy files from the device to the C2 server. ViceLeaker can copy arbitrary files from the device to the C2 server, can exfiltrate browsing history, can exfiltrate the SD card structure, and can exfiltrate pictures as the user takes them. TriangleDB has collected and exfiltrated files.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware family used by Arid Viper and distributed via weaponized apps masquerading as Telegram and Skipped Messenger. It requests extensive permissions, supports location access, call monitoring and recording, microphone/audio capture, contact and storage access, notification reading, account collection, file download, and C2 communications, while using obfuscation and anti-analysis techniques.
SpyC23 is an Android spyware family associated with the APT-C-23 group.
Android spyware that collects and exfiltrates selected file types such as PDF and DOC files.
Spyware that collects and exfiltrates files with selected extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.