logo

Operation Arid Viper: Bypassing the Iron Dome

ID: 10b9b380-94d9-4fda-8998-feed42e9160a

STIX ID: report--10b9b380-94d9-4fda-8998-feed42e9160a

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2015-02-13

Last Modified Date: 2015-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro researchers describe 'Operation Arid Viper' and the related 'Advtravel' campaign: targeted spear-phishing deliveries (RAR→SCR→EXE) used pornographic decoys to distract victims while backdoors/stealers registered unique system IDs and exfiltrated documents and mobile data to C2 servers hosted in Germany; the report enumerates C2 domains, IPs, HTTP paths, sample hashes, victim artifacts and control-panel logs, and presents attribution evidence tying infrastructure registrations and developer handles (e.g., Dev_hima, Khalid Samra, Mahmoud Hashem) to actors in Gaza/Egypt.