Arid Viper’s upgraded Android malware is AridSpy, a trojan that ESET observed downloading additional payloads after installation. Earlier analyzed versions were single-stage; the newer samples used multiple stages, making the change in delivery concrete. ESET reported campaigns targeting users in Palestine and Egypt in its June 13, 2024 analysis, but its report is not evidence that those campaigns remain active today.
What upgraded malware is Arid Viper using in Middle East cyber attacks?
The malware is AridSpy, an Android trojan distributed through fake apps and dedicated download websites. In the samples ESET analyzed, an installed app fetched later payloads from command-and-control infrastructure. That differs from the single-stage form described in earlier AridSpy analysis: the initial app no longer represented the whole malware chain. ESET said this multistage design helped the malware avoid detection, but the report establishes a change in the samples it investigated—not a complete picture of all the group’s capabilities.
ESET identified five campaigns using sites that offered apps carrying AridSpy. Three of the five were still active when ESET published its findings in June 2024; that is a dated snapshot, not a current campaign-status claim. ESET found six occurrences in its telemetry in Palestine and Egypt. Those are vendor detections, not an estimate of total infections or regional prevalence. Most Palestinian detections were associated with the fake Palestinian Civil Registry app.
ESET attributed AridSpy to Arid Viper with medium confidence, based on campaign targeting consistent with part of the group’s known victimology and a distribution script previously associated with the actor. The report is available from ESET Research.
#1 Best Overall
What is AridSpy?
AridSpy is the name ESET gave to malicious code found in Android apps distributed in the campaigns it examined. Three distributed apps were legitimate apps modified to include the spyware; other lures posed as messaging services, a job opportunity app, or a Palestinian Civil Registry app. A familiar service name or working-looking app is not proof that an app or download site is genuine.
Arid Viper is also known as APT-C-23, Desert Falcons, and Two-tailed Scorpion, among other names. MITRE ATT&CK groups these aliases under APT-C-23 and describes the actor as primarily focused on the Middle East, with Android and iOS spyware development dating to 2017. Its entry also records mobile phishing links and app masquerading as techniques. The group page’s July 31, 2026 modification date is a knowledge-base update date; it does not establish a new AridSpy campaign. See MITRE ATT&CK’s APT-C-23 entry.
Rank #2
How do fake Android apps infect phones?
ESET’s account describes a manual download-and-install flow, rather than an app installed through Google Play:
- A site impersonates a useful app or service. The dedicated sites promoted messaging apps, a job opportunity app, or a Palestinian Civil Registry app.
- The user downloads an installer from the site. ESET found the apps on third-party websites, not Google Play.
- Android requires a non-default installation setting. The user is prompted to allow installation of apps from unknown sources to proceed with the download.
- The installed app fetches later malware components. In the multistage samples, the trojanized app contacted command-and-control infrastructure to download first- and second-stage payloads.
ESET also found a JavaScript file named myScript.js on several sites. It generated or returned the file path used to download a malicious app. Researchers had previously linked a similar script to Arid Viper campaigns. ESET noted that code changes on one site could have been an attempt to avoid linking the campaign to the group; that was an assessment, not proof of operator intent.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How does the newer AridSpy differ from earlier versions?
| Aspect | Earlier analyzed AridSpy | Samples ESET examined in its June 2024 report |
|---|---|---|
| Payload staging | Single-stage, according to ESET’s description of earlier analyzed versions. | Multistage: the installed app downloaded later payloads from command-and-control infrastructure. |
| Distribution | Not stated for earlier versions in ESET’s June 2024 comparison. | Dedicated websites offering fake or trojanized Android apps. |
| Observed geography | Not stated for earlier versions in ESET’s June 2024 comparison. | ESET telemetry recorded six occurrences in Palestine and Egypt; this is not a total-infection estimate. |
| Attribution | Not stated for earlier versions in ESET’s June 2024 comparison. | ESET attributed the activity to Arid Viper with medium confidence. |
What is known about the campaigns’ timing and reach?
ESET published its campaign analysis on June 13, 2024, after detecting AridSpy in August 2023. It reported five campaigns and said three remained active at publication. Those dates do not show whether the sites or campaigns are active now. The six telemetry occurrences reported by ESET are limited to its own visibility and cannot establish how many people were infected.
For historical context, Meta’s April 2021 report described disrupting Arid Viper accounts and infrastructure, sharing indicators with industry partners, and notifying people believed to have been targeted. It described targeting in the Palestinian territories and Syria, and to a lesser extent Turkey, Iraq, Lebanon, and Libya. That earlier activity does not establish the geography or status of the 2024 AridSpy campaigns. Meta’s account is at Taking Action Against Hackers in Palestine.
Quick Recap
Rank #4
How can Android users reduce the risk?
- Install apps through Google Play or the service provider’s official website, and verify the site address independently before downloading.
- Be cautious when an app delivered by a website asks you to enable installation from unknown sources; do not treat a useful-looking app or recognizable branding as proof of authenticity.
- Avoid suspicious links and software downloads from sources you do not trust. Meta recommended these precautions in its 2021 report; they reduce exposure but cannot guarantee protection against spyware.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

