AridSpy

AppWizard
June 17, 2024
Arid Viper APT Group has been targeting Android users in the Middle East since 2022 through five campaigns. They use trojanized apps impersonating legitimate ones, such as messaging apps and a civil registry app. The AridSpy malware has evolved into a multi-stage trojan that downloads additional payloads from a command-and-control server. The group uses the myScript.js script to connect distribution websites and identify additional campaigns.
AppWizard
June 15, 2024
- ESET researchers discovered five campaigns targeting Android users in Egypt and Palestine with trojanized apps. - The campaigns started in 2022 and are believed to be orchestrated by the Arid Viper APT group. - Three of the campaigns are still active. - The spyware, known as AridSpy, is distributed through deceptive websites posing as popular messaging apps, a job search app, and a Palestinian Civil Registry app.
Search