Researchers and media reports said the Hamas-linked threat group APT-C-23 targeted high-ranking Israeli officials in a spear-phishing campaign designed to steal sensitive information from government and security figures. The operation, dubbed Operation Bearded Barbie by Cybereason, used social-engineering lures and fake personas to build trust with targets before delivering malware and harvesting data from compromised devices.
The campaign was attributed to a Palestinian cyber-espionage actor also tracked as Arid Viper, with reporting indicating the activity focused on Israeli public-sector and political targets. The operation combined tailored phishing messages, fraudulent online identities, and mobile-focused surveillance tooling to gain persistent access and collect intelligence, underscoring the group’s continued use of espionage tactics aligned with regional geopolitical interests.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
The Register reported on the Hamas-linked espionage campaign targeting high-ranking Israeli officials, reflecting public reporting of the same operation and its focus on senior Israeli figures. This was a later report on the campaign rather than a distinct new incident.
Cybereason reported that Hamas-linked threat group APT-C-23 conducted a campaign dubbed 'Operation Bearded Barbie' targeting Israeli government, military, and related officials with social-engineering lures and malware. The activity was described as an espionage operation focused on high-ranking Israeli targets.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetheregister.com
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.