Home
Glossary
AridViper
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
August 13, 2026

AridViper (aka APT-C-23, Desert Falcons) threat actor

AridViper is a cyber espionage intrusion set active since at least 2012, widely assessed to be associated with Hamas, the Palestinian politico-military organization. It conducts surveillance and intelligence collection against targets in Israel and the wider Middle East, and also against Palestinian individuals and organizations. Its defining characteristic is that it targets people rather than infrastructure: rather than looking for a flaw in a network, it builds fabricated social media personas, holds conversations with its targets, and persuades them to install spyware on their own phones and computers. It's also tracked as APT-C-23, Desert Falcon, and MoleRATs, among other names. Two things make AridViper worth understanding beyond its region. It's one of the most consistently mobile-focused espionage actors on record, with a long history of Android and iOS spyware at a time when most organizations monitor mobile devices far less closely than laptops. And its targeting runs in two directions at once, outward against geopolitical adversaries and inward against political opposition, which is unusual and shapes who's actually at risk. This page covers its names, its attribution, who it targets, how it operates, and how to defend against it, drawing on first-party research by Sekoia's Threat Detection & Research (TDR) team.

Key takeaways

  • AridViper is a cyber espionage intrusion set, active since at least 2012 and widely assessed to be associated with Hamas.
  • It targets people, not perimeters. Fabricated social media personas and tailored spearphishing persuade targets to install spyware themselves.
  • Mobile is central to its tradecraft. It has maintained Android and iOS spyware alongside Windows tooling for years, which puts it ahead of many defenders' visibility.
  • Its targeting runs in two directions. Espionage against Israeli and regional targets, and surveillance of Palestinian political opposition, civil society, and journalists.
  • The attribution is an assessment, not an adjudicated fact. No government indictment or formal attribution exists, so reporting including Sekoia's uses careful language.

AridViper's other names

This actor carries an unusually messy set of designations, and the confusion is substantive rather than cosmetic. The names you'll encounter include:

  • Arid Viper, written as one or two words
  • APT-C-23
  • Desert Falcon, sometimes Desert Falcons
  • MoleRATs, also written Molerats
  • Gaza Cybergang
  • Two-Tailed Scorpion
  • Mantis
  • Renegade Jackal

The important caveat is that these are not cleanly interchangeable, and analysts genuinely disagree about the boundaries. Some reporting treats MoleRATs and Gaza Cybergang as separate clusters that overlap with AridViper, while other analysis, including Sekoia's own, assesses MoleRATs to be an alias of the same intrusion set. This isn't a naming quibble: if you're reading a report to decide whether it describes a threat to your organization, the scope the author intended matters. Cross-reference designations, and check what activity a given report actually documents rather than trusting that two names mean the same thing.

Attribution and how confident to be about it

AridViper is widely assessed to be associated with Hamas, the Palestinian politico-military organization that has been the de facto governing authority of the Gaza Strip since 2007 and is designated a terrorist organization by the European Union and a number of other jurisdictions. The assessment rests on the pattern of targeting, which aligns with Hamas's political and military interests both externally and against its domestic rivals, and on more than a decade of analysis across the research community.

It's worth being precise about the strength of that attribution, because it differs from other actors in this glossary. Groups such as those linked to Russian or Chinese state services have been named in government indictments, sanctions designations, and formal joint attributions. AridViper has not. What exists is an analytic consensus, expressed with hedged language, and Sekoia's own published research reflects that by describing the group as allegedly or suspectedly associated with Hamas rather than confirmed. Sekoia assesses it as likely that the intrusion set contributes to intelligence collection on Hamas's geopolitical adversaries, and as possible that it contributes to surveillance of political opposition within Palestine. Those confidence qualifiers are deliberate and this page keeps them.

Who AridViper targets

The dual direction of the targeting is the most analytically interesting thing about this actor, and Sekoia's research sets it out as two distinct strands of activity.

AridViper targeting strands
Strand of activity Who is targeted
Espionage against regional adversaries Israeli government offices, military organizations and personnel, academic institutions, law enforcement and emergency services, alongside telecommunications, insurance, retail, and media organizations across the Middle East. Reported targets have also included entities in Bahrain and Algeria, as well as journalists and human rights activists in Turkey.
Surveillance of Palestinian targets Individuals in the Palestinian banking sector, people linked to Palestinian political movements, members of nongovernmental organizations operating in Gaza and the West Bank, and journalists. Sekoia assesses that this strand may support surveillance of political opposition, including rival movements and civil society groups critical of Hamas.

Lure themes have tracked regional politics closely, drawing on major events and on tensions between rival Palestinian movements, which is consistent with an operation that follows its targets' attention rather than working from a fixed template. For defenders outside the region, the relevant point is that journalists, researchers, non-governmental organizations, and academics working on Middle Eastern affairs fall within scope even when their employer has no regional presence.

How AridViper operates

AridViper's tradecraft is built on patience and impersonation rather than technical novelty, and that choice is what makes it effective.

  • Fabricated social media personas. The group builds accounts designed to look like real people, then engages targets in conversation before anything malicious appears. By the time a file or app is suggested, a relationship exists. This has been documented repeatedly against military personnel, where the approach exploits ordinary sociability rather than any technical weakness.
  • Tailored spearphishing. Messages and decoy documents built around subjects the target genuinely cares about, including regional political developments.
  • Mobile spyware. Android and iOS implants distributed as apps the target is persuaded to install, often through channels outside official app stores. This is the part of the toolkit most likely to sit outside an organization's monitoring.
  • Cross-platform desktop tooling. Windows implants that have been maintained and rewritten over years, with the group porting its own malware into new programming languages rather than abandoning it.
  • Broad collection once installed. Documented capabilities include uploading and downloading files, keystroke capture, microphone recording, and executing commands received from a command and control server. On mobile, that collection extends to the sensors and messages a phone carries.

The malware families associated with the group show its longevity: a long-running Windows implant that was later reimplemented in Python, a separate backdoor written in Go, and more recently one developed in Rust. An actor that keeps rebuilding the same capability in new languages is deliberately staying ahead of detection built around the old versions.

Sekoia's research on AridViper

Sekoia's TDR team published an analysis of AridViper in October 2023, combining a victimology review with its own technical investigation. The victimology work produced the two-strand model described above, separating outward-facing espionage from surveillance of Palestinian targets, and it's the framing that makes the actor's behaviour coherent rather than scattered.

On the technical side, TDR analysts extended existing published indicators and identified command and control domains previously undocumented, which were still live at the time of writing. From the pattern of when those domains were first observed resolving, the team assessed that the group's infrastructure was being regularly maintained and updated, and confirmed the intrusion set was active and still operating at that point.

What's equally worth noting is what Sekoia declined to claim. The research was published shortly after a major escalation in the regional conflict, a moment when there was considerable appetite for connecting cyber activity to events on the ground. TDR stated plainly that it found no evidence of AridViper increasing its activity before or during that period, and separately that it found no technical evidence supporting a hypothesis of coordination with Iranian intrusion sets, despite that hypothesis being a reasonable one to raise. Declining to fill an intelligence gap with a plausible story is what makes the rest of an assessment worth trusting.

How to defend against AridViper

Because this actor targets individuals through relationships and mobile devices, defence looks different from defending against a network-focused intruder:

  1. Treat mobile devices as in scope. If a phone can reach corporate email, chat, or documents, it needs the same consideration as a laptop. This actor's mobile focus makes unmanaged devices the likeliest gap.
  2. Restrict installation to official app stores. Sideloaded applications are a primary delivery route, and blocking installation from unknown sources removes much of it.
  3. Brief the people actually at risk. Staff working on regional affairs, journalists, researchers, and personnel in defence and government roles should know that a friendly, persistent stranger on social media is a documented technique, not a hypothetical one.
  4. Extend awareness beyond email. Training that covers only suspicious attachments misses an approach that begins with weeks of ordinary conversation on a social platform.
  5. Watch for the post-installation behaviour. Monitor for unfamiliar applications accessing microphones, capturing input, or making regular outbound connections to unfamiliar infrastructure, since these behaviours persist even as the implants get rewritten.
  6. Use current intelligence. Given how often this group rebuilds its tooling, tracking its infrastructure and techniques matters more than matching known files.

Why an actor that targets people is hard to keep out

Most security architecture assumes the adversary is trying to get through something: a perimeter, an authentication step, a vulnerable service. AridViper mostly isn't. It's trying to become someone a target trusts, and then to be helpful. The malicious moment in one of these operations is a person voluntarily installing an application because a contact they've been talking to for weeks suggested it. No control was bypassed. The user had the permission they used.

That's why the mobile dimension matters so much here. A phone is a sensor package with a microphone, a camera, a location history, and a copy of the owner's messages, and in many organizations it's also the least monitored device with access to corporate resources. An actor with a decade of mobile spyware development and a proven ability to talk people into installing things is aimed precisely at that gap. Sekoia is a European cybersecurity vendor whose in-house TDR team has tracked this intrusion set directly, mapping its victimology and finding live infrastructure it had not previously published, and that intelligence feeds the Sekoia AI SOC platform, where signals across endpoint, network, identity, and cloud are correlated and matched against rules mapped to the MITRE ATT&CK framework.

The honest position for a defender is that prevention will sometimes lose to this approach, because it targets judgment rather than technology. What can be arranged in advance is visibility over the devices that matter, awareness among the specific people most likely to be approached, and detection focused on what an implant does after it's installed rather than on recognizing the file that installed it. The behaviour outlasts the tooling, and with this actor the tooling changes often.