Desert Scorpion
MITRE ATT&CK: S0505 View on attack.mitre.org
Aliases: Desert Scorpion
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 14:06:59
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:ps
Context
Desert Scorpion is surveillanceware that has targeted the Middle East, specifically individuals located in Palestine. Desert Scorpion is suspected to have been operated by the threat actor APT-C-23. There are multiple close variants of Desert Scorpion, such as VAMP, GnatSpy, FrozenCell and SpyC23, which add some additional functionality but are not significantly different from the original malware.
Malware & tools used
- Archive Collected Data (attack-pattern)
- Out of Band Data (attack-pattern)
- Download New Code at Runtime (attack-pattern)
- Software Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- SMS Messages (attack-pattern)
- Audio Capture (attack-pattern)
- System Information Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Video Capture (attack-pattern)
- Contact List (attack-pattern)
- File Deletion (attack-pattern)
- Stored Application Data (attack-pattern)
- Location Tracking (attack-pattern)
- Code Signing Policy Modification (attack-pattern)
- Suppress Application Icon (attack-pattern)
- SMS Control (attack-pattern)
Used by threat actors
- APT-C-23 (threat-actor)
Reports & references
- Trend Micro — New Gnatspy Mobile Malware Family Discovered (report)
- Palo Alto Unit 42 — Unit42 Targeted Attacks Middle East Using Kasperagent Micropsia (report)
- MITRE ATT&CK — S0505 (report)
- blog.lookout.com — Desert Scorpion Google Play (report)