Phenakite
MITRE ATT&CK: S1126 View on attack.mitre.org
Aliases: Dakkatoni, Phenakite
- First seen
- 2021-06-01 00:00:00
- Malware type
- spyware, trojan
- Family
- Malware family
- Operating systems
- ios
- Profile updated
- 2026-07-07 13:19:38
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:ps country_code:il
Context
Phenakite is a mobile malware that is used by APT-C-23 to target iOS devices. According to several reports, Phenakite was developed to fill a tooling gap and to target those who owned iPhones instead of Windows desktops or Android phones.
Malware & tools used
- SMS Messages (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Data from Local System (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Audio Capture (attack-pattern)
- Input Capture (attack-pattern)
- System Information Discovery (attack-pattern)
- Video Capture (attack-pattern)
- Contact List (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
Used by threat actors
- APT-C-23 (threat-actor)
Reports & references
- web.archive.org — Technical Threat Report Arid Viper April 2021 (report)
- web.archive.org — The Israel Hamas War Cyber Domain State Sponsored Activity Of Interest (report)
- malpedia.caad.fkie.fraunhofer.de — Ios.Phenakite (report)
- malware4all.blogspot.com — Grab Your Own Copy Phenakite Ios (report)
- MITRE ATT&CK — S1126 (report)