Arid Viper poisons Android apps with AridSpy

ESET researchers identified five campaigns targeting Android users with trojanized apps that deploy multistage Android spyware called AridSpy. This malware, attributed with medium confidence to the Arid Viper APT group, focuses on user data espionage. AridSpy downloads additional payloads from its command-and-control server to avoid detection and exfiltrates sensitive information like contacts, messages, locations, and media files. Author: AlienVault

Related Tags:
AridSpy

exfiltration

Egypt

espionage

spyware

android

AlienVault OTX

AlienVault

Associated Indicators:
A4E74F74E675A08FDF8E0B55D5DA59AF8F1C67A2820C97BA6C6790B29589663D

5F0213BA62B84221C9628F7D0A0CF87F27A45A28

8FF57DC85A7732E4A9D144F20B68E5BC9E581300

16C8725362D1EBC8443C97C5AB79A1B6428FF87D

78F6669E75352F08A8B0CA155377EEE06E228F58

E71F1484B1E3ACB4C8E8525BA1F5F8822AB7238B

DB6B6326B772257FDDCB4BE7CF1A0CC0322387D8

3485A0A51C6DAE251CDAD20B2F659B3815212162

2158D88BCE6368FAC3FCB7F3A508FE6B96B0CF8A