Desert Scorpion

MITRE ATT&CK: S0505 View on attack.mitre.org

Aliases: Desert Scorpion

Malware type
spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:06:59

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:ps

Context

Desert Scorpion is surveillanceware that has targeted the Middle East, specifically individuals located in Palestine. Desert Scorpion is suspected to have been operated by the threat actor APT-C-23. There are multiple close variants of Desert Scorpion, such as VAMP, GnatSpy, FrozenCell and SpyC23, which add some additional functionality but are not significantly different from the original malware.

Malware & tools used

  • Archive Collected Data (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Download New Code at Runtime (attack-pattern)
  • Software Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • SMS Messages (attack-pattern)
  • Audio Capture (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Video Capture (attack-pattern)
  • Contact List (attack-pattern)
  • File Deletion (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Location Tracking (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • Suppress Application Icon (attack-pattern)
  • SMS Control (attack-pattern)

Used by threat actors

Reports & references

  • Trend Micro — New Gnatspy Mobile Malware Family Discovered (report)
  • Palo Alto Unit 42 — Unit42 Targeted Attacks Middle East Using Kasperagent Micropsia (report)
  • MITRE ATT&CK — S0505 (report)
  • blog.lookout.com — Desert Scorpion Google Play (report)

External references