NEW: Group Profiler — instant APT intel lookup. Try it →

APT-C-23

G1028 Espionage MITRE ATT&CK →

Also known as: Mantis · Arid Viper · Desert Falcon · TAG-63 · Grey Karkadann · Big Bang APT · Two-tailed Scorpion

Overview

APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile spyware targeting Android and iOS devices since 2017.

Naming & attribution

APT-C-23 is tracked under 8 names across the industry. It uses 0 documented ATT&CK techniques — more than 0% of the 174 groups tracked here. Activity attributed since at least 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
MantisSymantec Threat Hunter Team
Arid ViperStefanko, L
Desert FalconStefanko, L
Grey KarkadannHegel, T., Milenkoski, A
Big Bang APTKayal, A
Two-tailed ScorpionStefanko, L

Malware families with current indicators

One family attributed to APT-C-23, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Micropsia 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Civil society · Defense · Education · Energy · Finance · Government · High-Tech · Legal · Media · Military · NGOs · Telecommunications · Transportation

Regions

Europe · Israel · Middle East · Palestine · United States

Tools & malware (1)

Micropsia

Reporting (3)