Israeli investigators and multiple security firms reported that Hamas-linked operators ran a sustained mobile espionage campaign against Israeli soldiers by posing as attractive women on social media and persuading targets to install malicious Android apps. The lures included dating, World Cup, and other themed applications, and the operation reportedly compromised hundreds of devices before being disrupted. Israeli authorities tied the activity to Hamas, while private-sector researchers linked it with medium to high confidence to APT-C-23/Arid Viper based on targeting patterns, infrastructure, and tradecraft.
The malware was packaged in apps such as GrixyApp, ZatuApp, and Catch&See, then used fake error messages to reduce suspicion while hiding its icon and continuing to run in the background. Researchers said the implants harvested phone numbers, email addresses, SMS messages, location data, installed-app inventories, photos, and storage details, and in some cases enabled remote access to cameras and microphones or downloaded additional payloads via DEX files. Reporting also said Hamas used related mobile collection methods, including a fitness app, to identify soldiers near the Gaza border and gather intelligence on Israeli bases and armored vehicles.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
In January 2018, the Israeli military's information security department began receiving complaints from soldiers about suspicious social media contacts recommending mobile app downloads. These complaints helped surface the espionage campaign.
In 2017, the Israel Defense Forces published a report attributing a cyber campaign to Hamas that used fake Facebook profiles to target Israeli soldiers with Android malware. ClearSky described that earlier operation as similar to the later campaign.
Fake Facebook profiles were used beginning in 2017 to build trust with Israeli soldiers and persuade them to install malicious Android apps. A similar 2017 campaign was later described as having used multiple fake Facebook accounts to lure soldiers into installing Android malware.
Check Point reported that the Rebound campaign used Android RATs disguised as dating apps such as GrixyApp, ZatuApp, and Catch&See, with malware that hid itself after showing a fake unsupported-device error and communicated over MQTT. The researchers attributed the campaign to APT-C-23 based on overlapping tactics, infrastructure patterns, and thematic references.
The IDF and Israel Security Agency conducted a joint operation to take down a Hamas-linked campaign dubbed "Rebound" that targeted IDF soldiers with Android malware disguised as dating apps. The operation interrupted a social-engineering effort in which operators posed as attractive women and sent victims links to malicious apps.
ClearSky shared domains, APK names, and file hashes tied to the campaign and said it could not find direct technical overlap with a known actor. Based on targeting patterns, fake personas, and prior activity, it assessed with medium confidence that Arid Viper was likely behind the operation.
The Israel Defense Forces uncovered a campaign that used fake Facebook profiles to lure soldiers into installing Android malware and attributed it to Hamas. The campaign targeted Israeli soldiers directly through social engineering.
Hamas used fake dating and World Cup-themed Android apps, including Golden Cup, to hack the phones of hundreds of Israeli soldiers. The malware enabled access to photos, phone numbers, email addresses, and remote control of cameras and microphones, allowing intelligence collection on bases and armored vehicles.
After the complaints surfaced, Israeli military investigators determined that Hamas was behind the malicious apps used to compromise soldiers' Android phones. The military response effort was dubbed "operation broken heart."
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securelist.com
Open sourceresearch.checkpoint.com
Open sourceclearskysec.com
Open sourcehaaretz.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.