Arid Viper APT Group has been targeting Android users in the Middle East since 2022 through five campaigns. They use trojanized apps impersonating legitimate ones, such as messaging apps and a civil registry app. The AridSpy malware has evolved into a multi-stage trojan that downloads additional payloads from a command-and-control server. The group uses the myScript.js script to connect distribution websites and identify additional campaigns.