AridViper is a Palestinian APT group using custom mobile malware for intelligence gathering in Israel, the US, Europe, and the Middle East.
Analyst brief
AridViper is a Palestinian state-sponsored APT group primarily targeting government, defense, media, and civil society sectors in Israel, Palestine, the US, Europe, and the Middle East. They employ custom mobile malware (Micropsia, AridSpy) delivered through spear-phishing emails, deceptive apps, and fake social media profiles for data exfiltration. Defenders should focus on detecting suspicious mobile app installations, social engineering attempts, and anomalous data exfiltration patterns.
AridViper
Desert FalconArid ViperAPT-C-23
nation-state
AridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a focus on Israel and Palestine. The group employs custom-developed mobile malware, including variants like AridSpy, GnatSpy, and Micropsia, often delivered through spear-phishing emails and deceptive applications. Their operations involve sophisticated social engineering tactics, including the use of fake social media profiles and weaponized apps masquerading as legitimate services. AridViper's activities are characterized by a blend of technical sophistication and psychological manipulation, aiming to exfiltrate sensitive data from compromised systems.