Arid Viper is a Palestinian threat group, also tracked as APT-C-23, ALUMINUM SARATOGA, Desert Falcon, Molerats, Operation DustySky, Gaza Cybergang, Extreme Jackal, and TA402. The group has been active since at least 2011 and presents itself as the Gaza Hackers Team. It is primarily associated with espionage activity, with additional hacktivist behavior reported in the form of disruptive operations such as distributed denial-of-service attacks and website defacements. Its targeting has focused on organizations in the Middle East and North Africa. The group is known for targeted spearphishing operations used to gain initial access and deliver remote access malware. Reported tooling includes a mix of commodity and custom malware families such as PoisonIvy, XtremeRAT, QuasarRAT, DarkComet, BlackShades, NimbleMamba, BrittleBush, LastConn, and Micropsia. Public reporting links the actor to phishing campaigns that used actor-controlled delivery infrastructure and cloud-hosted links to stage payloads. Overall, Arid Viper is best characterized as a long-running Palestinian espionage actor that combines social-engineering-driven intrusion activity with occasional disruptive and hacktivist operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage and hacktivism threat group profiled in the listing.
Espionage and hacktivism activity cluster active since at least 2011, conducting targeted spearphishing, DDoS attacks, and website defacements against Middle Eastern and North African targets; late 2021/early 2022 campaigns used phishing lures with actor-controlled infrastructure and Dropbox links delivering NimbleMamba and BrittleBush.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.