Sphinx, also tracked as APT-C-15, is a cyberespionage threat actor associated with operations targeting Arabic-speaking users and countries in the Middle East, with Egypt featuring prominently in observed lures and themes. The actor has been linked to both Windows and Android malware activity and is known for using social engineering and watering-hole style delivery through social media-related channels. Sphinx has been observed delivering a customized version of njRAT on desktop systems and has been linked to the Android spyware family AnubisSpy through shared infrastructure, similar file structures, and overlapping regional targeting. Sphinx operations have used malware disguised as legitimate applications and themed around Middle Eastern news, sociopolitical topics, and Egypt-related content. The linked AnubisSpy tooling was distributed through malicious mobile applications in official and third-party app marketplaces and was capable of extensive surveillance, including theft of SMS messages, contacts, email accounts, calendar data, browser history, media files, screenshots, audio, phone calls, and data from popular messaging and social applications. The malware also supported remote command execution, file deletion, application installation and removal, encrypted data exfiltration, and self-removal. Observed tradecraft indicates a focus on covert collection and long-term victim monitoring rather than disruptive or financially motivated operations. Reported activity places the campaign in operation at least during the mid-2010s, with public reporting tying core Sphinx activity to the 2014–2015 period and related Android activity extending into 2017. Sphinx should be distinguished from unrelated malware or ransomware families that also use the name “Sphinx.”
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as the predecessor/spinoff lineage for Anubis.
Mentioned as a past user of njRAT for information theft and espionage.
Cyberespionage campaign linked to AnubisSpy, targeting Arabic-speaking users and Middle Eastern countries, using social engineering and mobile/desktop malware to spy on victims and steal data.
Cyberespionage campaign linked to AnubisSpy mobile spyware and previously associated with desktop/PC-targeting malware, reportedly using watering hole delivery via social media and a customized njRAT, with targets concentrated in the Middle East.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.