APT-C-23, also known as Two-tailed Scorpion or C-23, deployed updated Android spyware against users in the Middle East, with reporting pointing to victims especially in the Palestinian Territories. The malware was disguised as benign update or installer apps, including "App Updates," "System Apps Updates," "Android Update Intelligence," and a fake Google Play or Telegram-themed application using the package name org.telegram.light. Researchers said the campaign likely relied on phishing links sent by SMS and fake Android app stores to trick targets into installing the spyware and granting high-risk permissions such as device administrator, notification access, accessibility monitoring, and third-party app installation.
The newer variants expanded both stealth and resilience. After installation, the spyware could rename itself and swap icons to resemble trusted apps such as Google Play, YouTube, Google, or Botim, making removal harder for victims. It also supported post-deployment command-and-control updates and Firebase-based messaging to maintain communications if infrastructure changed. Once active, the malware could exfiltrate SMS messages, contacts, call logs, files, screenshots, audio recordings, pictures, and notifications from messaging apps including WhatsApp, while also placing calls, disabling Wi‑Fi, and in some cases deleting device data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On September 15, 2021, Cyble Research Labs published analysis of a new Android spyware variant attributed to APT-C-23 targeting users in the Middle East. The malware masqueraded as a Google Play installer with Telegram-like branding and sought extensive permissions to steal data and control infected devices.
ESET documented an Android espionage campaign in the Middle East built around a malicious chat app called Welcome Chat that functioned as a real messenger while covertly stealing SMS messages, call logs, contacts, photos, recordings, location, and device data. The researchers linked the operation to the long-running BadPatch campaign associated with Gaza Hackers/Molerats based on shared infrastructure and malware-family overlap.
Sophos said the C-23 threat actor, also known as GnatSpy, FrozenCell, and VAMP, has been active since at least 2017. This establishes the earliest explicitly dated activity mentioned in the references.
Sophos analyzed newly discovered Android spyware variants attributed to C-23 that improved persistence, stealth, and resilience, including the ability to change command-and-control addresses after deployment and disguise themselves as legitimate apps. Sophos said the campaign targeted individuals in the Middle East, especially in the Palestinian Territories, and shared details with the Android security team.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceblog.cyble.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.