HomeSecurityArid Viper hackers distribute AridSpy spyware via apps

Arid Viper hackers distribute AridSpy spyware via apps

Arid Viper hackers have been linked to a spyware campaign that leverages malicious Android apps to distribute a type of spyware called AridSpy .

AridSpy spyware hackers Arid Viper

“The malware is distributed via dedicated websites that impersonate various messaging apps, a job search app, and a Palestinian Civil Registry app,” said researcher Lukáš Štefanko. “These are often existing apps that have been infected and acquired the AridSpy malicious code.”

At least five campaigns are said to have taken place since 2022, with earlier variants of AridSpy being analyzed by Zimperium and 360 Beacon Labs. Three of the five campaigns are still active.

The Arid Viper hackers, also known as APT-C-23, Desert Falcon, Gray Karkadann, Mantis, and Two-tailed Scorpion, are believed to be affiliated with Hamas and have carried out various mobile malware attacks since 2017.

“The Arid Viper group has targeted military personnel in the Middle East, as well as journalists and dissidents,” SentinelOne noted late last year.

ESET's latest analysis of the new version of the AridSpy spyware shows that it has transformed into a trojan that can download additional payloads from a command-and-control (C2) position.

The targets are primarily users in Palestine and Egypt via fake sites that act as distribution points for the malicious apps. The malicious apps are designed to be unobtrusive and claim to be secure messaging services such as LapizaChat, NortirChat and ReblyChat. Each is based on legitimate apps such as StealthChat, Session and Voxer Walkie Talkie Messenger, while another app is purported to be from the Palestinian Civil Registry.

The Palestinian Civil Registry (“palcivilreg[.]com”), which was registered on May 30, 2023, was also found to be advertised through a dedicated Facebook page that has 179 followers. The app being spread through the website is inspired by an app of the same name available on the Google Play Store.

“The malicious application available on palcivilreg[.]com is not a trojanized version of the application on Google Play. However, it uses the legitimate server of this application to retrieve information,” Štefanko said. “This means that the Arid Viper hackers were inspired by the functionality of this application, but created their own client layer that communicates with the legitimate server.”

Another application that AridSpy spware spreads with is a job opportunities application from a website (“almoshell[.]site”) registered in August 2023. This is not based on any legitimate application.

During installation, the malicious application checks for the presence of security and, if not, proceeds to download a first-stage payload. The payload impersonates an update for Google Play Services.

“This payload operates separately, without the need for the trojanized application to be installed on the same device,” Štefanko explained. “This means that if the victim uninstalls the original trojanized application, for example LapizaChat, the AridSpy spyware will not be affected.”

The primary responsibility of the first stage is to download the next stage component, which hosts the malicious functionality and makes use of a Firebase domain for C2 purposes.

Arid Viper hackers distribute AridSpy spyware via apps

The software supports a wide range of commands for collection data. Data extraction is initiated either via command or when a specially defined event is triggered.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“If the victim locks or unlocks the phone, the AridSpy spyware will take a photo using the front camera and send it to the C&C server,” Štefanko said. “Photos are only taken if more than 40 minutes have passed since the last photo was taken and the battery level is above 15 percent.”

How can someone protect their digital life from spyware?

One of the most effective ways to protect yourself is to use reliable security. These programs scan your device for spyware and remove it (e.g. AridSpy). They also offer real-time protection, alerting you when an application tries to install spyware on your computer.

It's also important to keep your operating system and all programs up to date. These updates often include security fixes that can help protect your computer from spyware.

Another important tip is to be careful with the emails and messages you receive. This software is often spread through phishing, where attackers try to convince you to click on a malicious link or open a dangerous attachment.

Finally, it's important to keep backups of your important files. While this won't directly protect you from spyware, it will help you recover your data if your computer is infected.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS