Phenakite

MITRE ATT&CK: S1126 View on attack.mitre.org

Aliases: Dakkatoni, Phenakite

First seen
2021-06-01 00:00:00
Malware type
spyware, trojan
Family
Malware family
Operating systems
ios
Profile updated
2026-07-07 13:19:38

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:ps country_code:il

Context

Phenakite is a mobile malware that is used by APT-C-23 to target iOS devices. According to several reports, Phenakite was developed to fill a tooling gap and to target those who owned iPhones instead of Windows desktops or Android phones.

Malware & tools used

  • SMS Messages (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Audio Capture (attack-pattern)
  • Input Capture (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Video Capture (attack-pattern)
  • Contact List (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)

Used by threat actors

Reports & references

  • web.archive.org — Technical Threat Report Arid Viper April 2021 (report)
  • web.archive.org — The Israel Hamas War Cyber Domain State Sponsored Activity Of Interest (report)
  • malpedia.caad.fkie.fraunhofer.de — Ios.Phenakite (report)
  • malware4all.blogspot.com — Grab Your Own Copy Phenakite Ios (report)
  • MITRE ATT&CK — S1126 (report)

External references