Operation Arid Viper: Bypassing the Iron Dome
ID: 10b9b380-94d9-4fda-8998-feed42e9160a
STIX ID: report--10b9b380-94d9-4fda-8998-feed42e9160a
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2015-02-13
Last Modified Date: 2015-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro researchers describe 'Operation Arid Viper' and the related 'Advtravel' campaign: targeted spear-phishing deliveries (RAR→SCR→EXE) used pornographic decoys to distract victims while backdoors/stealers registered unique system IDs and exfiltrated documents and mobile data to C2 servers hosted in Germany; the report enumerates C2 domains, IPs, HTTP paths, sample hashes, victim artifacts and control-panel logs, and presents attribution evidence tying infrastructure registrations and developer handles (e.g., Dev_hima, Khalid Samra, Mahmoud Hashem) to actors in Gaza/Egypt.
