SpyC23
MITRE ATT&CK: S1195 View on attack.mitre.org
Aliases: SpyC23
- First seen
- 2017-01-01 00:00:00
- Malware type
- spyware, rat
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 13:19:36
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:sa country_code:ae country_code:jo country_code:eg
Context
SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017. SpyC23 has been observed primarily targeting Android devices in the Middle East. There are multiple close variants of SpyC23, such as VAMP, GnatSpy, Desert Scorpion and FrozenCell, which add some additional functionality but are not significantly different from the original malware.
Malware & tools used
- Call Control (attack-pattern)
- User Evasion (attack-pattern)
- Data from Local System (attack-pattern)
- Access Notifications (attack-pattern)
- Broadcast Receivers (attack-pattern)
- Video Capture (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Location Tracking (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- SMS Control (attack-pattern)
- Contact List (attack-pattern)
- Audio Capture (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Suppress Application Icon (attack-pattern)
- Call Log (attack-pattern)
- Out of Band Data (attack-pattern)
- Web Protocols (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
- Screen Capture (attack-pattern)
- SMS Messages (attack-pattern)
Used by threat actors
- APT-C-23 (threat-actor)
Reports & references
- web.archive.org — Aptc23 Group Evolves Its Android Spyware (report)
- Trend Micro — New Gnatspy Mobile Malware Family Discovered (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Spyc23 (report)
- ESET — Aptc23 Group Evolves Its Android Spyware (report)
- Palo Alto Unit 42 — Unit42 Targeted Attacks Middle East Using Kasperagent Micropsia (report)
- MITRE ATT&CK — S1195 (report)