SpyC23 is an Android spyware family associated with the Palestinian threat actor Arid Viper, also tracked as APT-C-23 and related aliases. Active since at least 2019, it has been used in espionage operations targeting victims in the Middle East, with reporting indicating particular interest in Arabic-speaking users as well as historical targeting of military personnel, journalists, dissidents, and Palestinian and Israeli targets.
SpyC23 is typically distributed through weaponized Android applications masquerading as legitimate software, including Telegram-themed apps and romance- or dating-themed lures. Its operators have relied on social engineering to induce installation of trojanized APKs outside trusted channels. The malware has also shown code and functional overlap with other Arid Viper Android malware families, including GnatSpy, FrozenCell, and VAMP, indicating sustained toolchain evolution within the same espionage ecosystem.
On infected devices, SpyC23 supports broad surveillance and data-theft functions. Documented capabilities include reading and exfiltrating SMS messages, sending SMS messages, stealing contact lists and call logs, and collecting files with selected document-oriented extensions from device storage. It communicates with command-and-control infrastructure over HTTPS and can also use Firebase Cloud Messaging to support command delivery and operational resilience.
SpyC23 also implements Android persistence through event-triggered execution. It has been observed listening for device boot completion events so that malicious functionality can be activated automatically after reboot. Recent variants have incorporated obfuscation, anti-decompilation, and anti-virtualization measures to hinder analysis. Additional functionality reported in newer samples includes permission-heavy surveillance features such as location access, notification reading, file download support, and call-recording components, consistent with its role as a mobile espionage platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SpyC23 listens for the BOOT_COMPLETED broadcast to activate malware.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The developer employed anti-decompilation and anti-virtualization techniques to complicate analysis. Each of these APKs contains application code that is obfuscated.
The application permissions give a high degree of control over the device, including: Read & Write to storage
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
DEFENSOR ID has used Firebase Cloud Messaging for C2; Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging; Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions.
Brodie contains a method named isProbablyArabic... Panda imports methods from the OKhttp library to craft HTTP requests.
DEFENSOR ID has used Firebase Cloud Messaging for C2. Rotexy can also communicate by using JSON messages sent through Google Cloud Messaging. Skygofree can be controlled via HTTP, XMPP, FirebaseCloudMessaging, or GoogleCloudMessaging in older versions. SpyC23 can communicate with the Command and Control server using HTTPS and Firebase Cloud Messaging (FCM). Trojan-SMS.AndroidOS.Agent.ao uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.FakeInst.a uses Google Cloud Messaging (GCM) for command and control. Trojan-SMS.AndroidOS.OpFake.a uses Google Cloud Messaging (GCM) for command and control.
Examples in the content include: 'Riltok can access and upload the device's contact list to the command and control server,' 'Rotexy can access and upload the contacts list to the command and control server,' and multiple entries stating malware can 'exfiltrate' contacts.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the ALUMINUM SHADYSIDE threat profile.
Android spyware family used by Arid Viper and distributed via weaponized apps masquerading as Telegram and Skipped Messenger. It requests extensive permissions, supports location access, call monitoring and recording, microphone/audio capture, contact and storage access, notification reading, account collection, file download, and C2 communications, while using obfuscation and anti-analysis techniques.
SpyC23 is an Android spyware family associated with the APT-C-23 group.
Android spyware that collects and exfiltrates selected file types such as PDF and DOC files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.