According to recent reports, Arabic-speaking Android users have been targeted with spyware by the “Arid Viper” threat actor, also known as APT-C-23, Desert Falcon, or TAG-63). This threat actor has been using counterfeit dating apps designed to exfiltrate data from compromised devices.
Arid Viper is a cyber espionage group that has been active since 2017. This threat actor has been speculated to be associated with Hamas, an Islamist militant movement. To compromise victims, Arid Viper uses malicious links masquerading as updates to dating applications that deliver malware to the user’s device.
The malware supplied by the threat group appears to have similarities with a legitimate online dating application called “Skipped” which creates suspicion as to whether the threat actors are linked with the application’s developers or acquired a copy of the application’s feature to spoof.
Ensure your Cyber Resiliance with the recent wave of cyber-attacks targeting the financial services sector. Almost 60% respondents not confident to recover fully from a cyber attack.
However, there were also other applications detected that have similar themes like “Skipped” and are available in the Google Play Store and App Store.
The applications were VIVIO, Meeted, SKIPPED, and Joostly. Skipped and Joostly combined contain 60,000 downloads on the Google Play Store.
Once installed, this malware hides itself by turning off security notifications from any Android OS containing the “security” APK package.
It also requests for permissions like microphone, camera, contacts, call logs, SMS messages, Wi-Fi settings, background applications, Photos, and SYSTEM for malicious purposes.
Additionally, the malware is also capable of retrieving system information, updating the C & C domain from the current C2, and downloading additional malware that is hidden under legitimate app names like Facebook, Messenger, Instagram, and WhatsApp.
A complete report about this malware has been published by Cisco Talos, which provides detailed information about the malware, threat actor, and other additional information.
Cisco Talos has provided a GitHub repository containing IOCs related to this research.
Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Try a free trial to ensure 100% security.
In a significant development, the Trump administration is reportedly formulating a plan to prevent a…
IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory Integrator…
A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through 9.7.0.…
A cybersecurity researcher recently disclosed several critical vulnerabilities affecting Git-related projects, revealing how improper handling…
Researchers from IIT Kharagpur and Intel Corporation have identified a significant security vulnerability in Intel…
Burp Suite 2025.1, is packed with new features and enhancements designed to improve your web…