AridViper__2020__APT_C_23_group_evolves_its_Android_spyware_WeLiveSecurity.pdf
ID: a5f6278b-56ab-4fb5-b888-d1d6e1de4b8f
STIX ID: report--a5f6278b-56ab-4fb5-b888-d1d6e1de4b8f
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2020-10-08
Last Modified Date: 2020-10-08
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers describe a new variant of Android spyware (Android/SpyC23.A) used by APT‑C‑23 (Two‑tailed Scorpion) that impersonates messaging apps and fake app stores to persuade victims to grant invasive permissions; the malware can record audio, camera, screen and calls (including WhatsApp), read notifications from popular messaging apps, exfiltrate contacts/SMS/files, hide itself, dynamically resolve obfuscated C2 servers and includes multiple IoCs and hashes — ESET recommends installing apps only from Google Play and using updated mobile security.
