logo

AridViper__2020__APT_C_23_group_evolves_its_Android_spyware_WeLiveSecurity.pdf

ID: a5f6278b-56ab-4fb5-b888-d1d6e1de4b8f

STIX ID: report--a5f6278b-56ab-4fb5-b888-d1d6e1de4b8f

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2020-10-08

Last Modified Date: 2020-10-08

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET researchers describe a new variant of Android spyware (Android/SpyC23.A) used by APT‑C‑23 (Two‑tailed Scorpion) that impersonates messaging apps and fake app stores to persuade victims to grant invasive permissions; the malware can record audio, camera, screen and calls (including WhatsApp), read notifications from popular messaging apps, exfiltrate contacts/SMS/files, hide itself, dynamically resolve obfuscated C2 servers and includes multiple IoCs and hashes — ESET recommends installing apps only from Google Play and using updated mobile security.