APT-C-23
Also known as: Mantis · Arid Viper · Desert Falcon · TAG-63 · Grey Karkadann · Big Bang APT · Two-tailed Scorpion
Overview
APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile spyware targeting Android and iOS devices since 2017.
Naming & attribution
APT-C-23 is tracked under 8 names across the industry. It uses 0 documented ATT&CK techniques — more than 0% of the 174 groups tracked here. Activity attributed since at least 2014.
| Name | First reported by |
|---|---|
| Mantis | Symantec Threat Hunter Team |
| Arid Viper | Stefanko, L |
| Desert Falcon | Stefanko, L |
| Grey Karkadann | Hegel, T., Milenkoski, A |
| Big Bang APT | Kayal, A |
| Two-tailed Scorpion | Stefanko, L |
Malware families with current indicators
One family attributed to APT-C-23, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Micropsia 1 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Civil society · Defense · Education · Energy · Finance · Government · High-Tech · Legal · Media · Military · NGOs · Telecommunications · Transportation
Regions
Europe · Israel · Middle East · Palestine · United States
Tools & malware (1)
Micropsia
Reporting (3)
- The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest — Hegel, T., Milenkoski, A
- Mantis: New Tooling Used in Attacks Against Palestinian Targets — Symantec Threat Hunter Team
- Technical Paper // Taking Action Against Arid Viper — Flossman, M., Scott, M