Phenakite is custom iOS spyware used by Arid Viper, also known as Desert Falcon and APT-C-23, for targeted cyberespionage. Publicly identified in April 2021, it was embedded in Magic Smile, a trojanized but functional chat application built using the open-source RealtimeChat code. Its deployment was associated with campaigns targeting Palestinian government officials, Fatah members, student groups, and security forces.
Initial installation relies on social engineering: victims are persuaded to install a mobile configuration profile that enables installation of a device-specific signed application. The device need not already be jailbroken. After installation, Phenakite uses bundled Osiris jailbreak and Sock Port exploit code to elevate privileges and access sensitive information beyond normal iOS application permissions. Distribution used a third-party application development platform and attacker-controlled hosting infrastructure.
Phenakite collects and exfiltrates contacts, SMS messages, device metadata, photos, WhatsApp media, selected documents, and messages exchanged through its trojanized chat application. It can record phone-call audio, silently capture audio, and take photographs using the device camera. During chat registration, it can redirect users to Facebook and iCloud phishing pages to steal credentials.
Its observed deployment was limited rather than widespread. Revocation of developer certificates disrupted distribution and appeared to pause Arid Viper's iOS operations in 2021.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For iOS devices, the group used Phenakite, which is capable of recording phone call audio, collecting and forwarding WhatsApp media files, photos, and files with specific extensions.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Android malware was typically hosted on convincing looking attacker-controlled phishing sites. At the time of this writing, we discovered 41 such sites.
Post-installation, a jailbreak was necessary for the malware to elevate its privileges to retrieve sensitive user information not accessible via standard iOS permission requests. This was achieved with the publicly available Osiris jailbreak that made use of the Sock Port exploit.
Retrieve photos from the camera roll ... Retrieve contacts ... Retrieve text messages ... Search for and return the path of files with a doc or PDF extension
This malware could also direct people to phishing pages for Facebook and iCloud to steal their credentials for those services.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A short-lived iOS implant associated with Arid Viper.
iOS spyware capable of recording calls, stealing WhatsApp media, photos, selected files, and redirecting victims to phishing pages to steal credentials.
Phenakite is identified as a named iOS malware sample/family.
iOS espionage malware used by Desert Falcons to record call audio and collect media, photos, and selected files. It also redirects victims to Facebook and iCloud phishing pages to steal credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.