Files
cti/mobile-attack/intrusion-set/intrusion-set--8332952e-b86b-486b-acc3-1c2a85d39394.json
2026-04-27 15:19:48 -04:00

98 lines
5.2 KiB
JSON

{
"type": "bundle",
"id": "bundle--548292ac-ee7e-4ee9-ab36-d9286017fe7c",
"spec_version": "2.0",
"objects": [
{
"modified": "2024-11-17T20:01:55.806Z",
"name": "APT-C-23",
"description": "[APT-C-23](https://attack.mitre.org/groups/G1028) is a threat group that has been active since at least 2014.(Citation: symantec_mantis) [APT-C-23](https://attack.mitre.org/groups/G1028) has primarily focused its operations on the Middle East, including Israeli military assets. [APT-C-23](https://attack.mitre.org/groups/G1028) has developed mobile spyware targeting Android and iOS devices since 2017.(Citation: welivesecurity_apt-c-23)",
"aliases": [
"APT-C-23",
"Mantis",
"Arid Viper",
"Desert Falcon",
"TAG-63",
"Grey Karkadann",
"Big Bang APT",
"Two-tailed Scorpion"
],
"x_mitre_deprecated": false,
"x_mitre_version": "1.0",
"x_mitre_contributors": [
"Sittikorn Sangrattanapitak"
],
"type": "intrusion-set",
"spec_version": "2.1",
"id": "intrusion-set--8332952e-b86b-486b-acc3-1c2a85d39394",
"created": "2024-03-26T18:38:00.759Z",
"created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
"revoked": false,
"external_references": [
{
"source_name": "mitre-attack",
"url": "https://attack.mitre.org/groups/G1028",
"external_id": "G1028"
},
{
"source_name": "Big Bang APT",
"description": "(Citation: checkpoint_interactive_map_apt-c-23) "
},
{
"source_name": "Grey Karkadann",
"description": "(Citation: sentinelone_israel_hamas_war)"
},
{
"source_name": "Mantis",
"description": "(Citation: symantec_mantis)(Citation: sentinelone_israel_hamas_war)"
},
{
"source_name": "Two-tailed Scorpion",
"description": "(Citation: welivesecurity_apt-c-23)"
},
{
"source_name": "Arid Viper",
"description": "(Citation: welivesecurity_apt-c-23)(Citation: sentinelone_israel_hamas_war)(Citation: fb_arid_viper)"
},
{
"source_name": "Desert Falcon",
"description": "(Citation: welivesecurity_apt-c-23)(Citation: sentinelone_israel_hamas_war)(Citation: fb_arid_viper)"
},
{
"source_name": "fb_arid_viper",
"description": "Flossman, M., Scott, M. (2021, April). Technical Paper // Taking Action Against Arid Viper. Retrieved November 17, 2024.",
"url": "https://web.archive.org/web/20231126111812/https:/about.fb.com/wp-content/uploads/2021/04/Technical-threat-report-Arid-Viper-April-2021.pdf"
},
{
"source_name": "sentinelone_israel_hamas_war",
"description": "Hegel, T., Milenkoski, A. (2023, October 24). The Israel-Hamas War | Cyber Domain State-Sponsored Activity of Interest. Retrieved March 4, 2024.",
"url": "https://web.archive.org/web/20240208234008/www.sentinelone.com/labs/the-israel-hamas-war-cyber-domain-state-sponsored-activity-of-interest/"
},
{
"source_name": "checkpoint_interactive_map_apt-c-23",
"description": "Kayal, A. (2018, August 26). Interactive Mapping of APT-C-23. Retrieved March 4, 2024.",
"url": "https://web.archive.org/web/20230604112435/https://research.checkpoint.com/2018/interactive-mapping-of-apt-c-23/"
},
{
"source_name": "welivesecurity_apt-c-23",
"description": "Stefanko, L. (2020, September 30). APT\u2011C\u201123 group evolves its Android spyware. Retrieved March 4, 2024.",
"url": "https://web.archive.org/web/20201123042131/www.welivesecurity.com/2020/09/30/aptc23-group-evolves-its-android-spyware/"
},
{
"source_name": "symantec_mantis",
"description": "Symantec Threat Hunter Team. (2023, April 4). Mantis: New Tooling Used in Attacks Against Palestinian Targets. Retrieved March 4, 2024.",
"url": "https://web.archive.org/web/20231227054130/https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks"
}
],
"object_marking_refs": [
"marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
],
"x_mitre_attack_spec_version": "3.2.0",
"x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
"x_mitre_domains": [
"mobile-attack",
"enterprise-attack"
]
}
]
}