Threat reportMalwareTL-2026-0192
Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users
Trojanized Red Alert Rocket Warning App (TL-2026-0192), also tracked as RedAlert Trojan Campaign, is a high-severity malware campaign scored CVSS 7.5, first published 2026-03-07. It is attributed to APT-C-23 (Palestine) with medium confidence, affects N/A (Trojanized third-party app) Red Alert / Oref Alert (Trojanized), maps to 15 MITRE ATT&CK techniques (T1406, T1407, T1417), and is covered by 9 detection rules and 26 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 1APT-C-23
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0192
- Threat ID
- TL-2026-0192
- Also known as
- RedAlert Trojan Campaign, Red Alert Mobile Espionage Campaign
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
- Status
- MONITORING
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- APT-C-23
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Palestine
- Motivation
- ESPIONAGE
- Target sectors
- government, military, civilian, critical-infrastructure
- Target regions
- Israel, Middle East
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Trojanized Red Alert Rocket Warning App
Malware and tooling: RedAlert Trojan
How Trojanized Red Alert Rocket Warning App works
A mobile spyware campaign attributed to Arid Viper (APT-C-23) distributes a trojanized version of Israel's Red Alert rocket warning Android application via SMS phishing. The malicious app impersonates the legitimate civil defense app, retaining full alert functionality while exfiltrating SMS messages, contacts, GPS location, and account data to attacker-controlled C2 infrastructure.
A sophisticated mobile spyware campaign is actively targeting Israeli civilians by distributing a trojanized version of the Red Alert (Oref Alert) rocket warning application for Android. The campaign leverages SMS phishing (smishing) messages that impersonate Israel's Home Front Command, urging recipients to install what appears to be an urgent wartime update to the emergency alert application.
The malicious APK (package name com.red.alertx) employs a multi-stage architecture designed for stealth and persistence. Stage 1 functions as a loader that uses a custom IPackageManagerSignatureProxyLoader to hook the Android PackageManager via dynamic proxy and Java reflection. This proxy intercepts signature verification calls and returns a hardcoded Base64-encoded X.509 certificate (originally issued 2014-07-12, valid until 2114-06-18) that impersonates the legitimate Home Front Command app's signing credential. The loader also forces getInstallerPackageName() to return com.android.vending, making the app appear as though it was installed from the Google Play Store.
Stage 2 extracts a hidden asset file named 'umgdn' from the APK's assets directory. This file contains the legitimate Red Alert application, which is loaded into memory by overwriting Android runtime fields (mAppDir, sourceDir, publicSourceDir). The legitimate app runs in the foreground providing real rocket alerts, while the spyware payload operates silently in the background.
Stage 3 deploys the core spyware module (DebugProbesKt.dex) which requests 20 Android permissions, 6 of which are security-sensitive: ACCESS_FINE_LOCATION (GPS tracking with geofencing), READ_SMS (full SMS database extraction via Telephony.Sms.CONTENT_URI), READ_CONTACTS (contact harvesting with phone numbers and emails), GET_ACCOUNTS (device account enumeration via reflection-based AccountManager invocation), RECEIVE_BOOT_COMPLETED (persistence across reboots), and SYSTEM_ALERT_WINDOW (overlay capability for credential phishing).
The malware employs aggressive obfuscation including Base64-encoded strings with unique 32-byte XOR keys per string, class/method name randomization, trivial wrapper functions to obscure control flow, and runtime reflection for all sensitive API calls. Installed applications are enumerated via PackageManager and exfiltrated in batches of 200.
All harvested data is staged locally and continuously transmitted via HTTPS POST requests to the C2 endpoint at api.ra-backup.com/analytics/submit.php. The C2 domain ra-backup.com was registered on June 23, 2025 through Namecheap, with infrastructure hosted across AWS (44.208.242.141, 44.200.176.254) and fronted by Cloudflare (104.21.64.137, 172.67.137.156).
The campaign was discovered on March 1, 2026 when the APK was submitted to VirusTotal (achieving only 3/65 detections initially) and Israeli citizens began reporting suspicious SMS messages on social media. Acronis Threat Research Unit (TRU) completed full analysis by March 2, and the Israeli National Cyber Directorate issued public warnings by March 6.
Attribution analysis links the campaign to Arid Viper (APT-C-23 / Desert Falcons / Two-tailed Scorpion), a Hamas-aligned cyberespionage group active since at least 2013 with a history of deploying surveillance malware targeting Israeli users across Android, iOS, and Windows platforms. The use of trojanized Android applications, targeting of Israeli civilians, and spyware capabilities are consistent with Arid Viper's established operational patterns. However, researchers note these indicators are not uniquely attributable — a similar 2023 campaign was attributed to hacktivist group AnonGhost.
---
**Revalidated on 2026-03-12**
This threat has been extensively validated through multi-vendor corroboration across at least 10 independent security organizations. The campaign was first detected on March 1, 2026 when Israeli citizens reported suspicious SMS messages on social media, and was independently analyzed by Acronis TRU (primary discoverer), CloudSEK, Palo Alto Unit 42, Infosecurity Magazine, The Register, Hackread, GBHackers, CyberPress, RedPacket Security, and PCRisk. The Israeli National Cyber Directorate issued official warnings. CloudSEK's analysis revealed additional infrastructure details beyond the original reporting: five C2/infrastructure IP addresses (216.45.58.148 on QuadraNet, 44.208.242.141 and 44.200.176.254 on AWS, 104.21.64.137 and 172.67.137.156 on Cloudflare), a third-stage payload (DebugProbesKt.dex) not previously documented in our threat record, and four distribution URLs including compromised WordPress site shirideitch[.]com and three bit.ly shortened links (3Ozydsn, 2O3fHEX, 3GfZoys). AV detection has increased substantially from the initial 3/65 on VirusTotal to broad coverage including Avast (APK:RepMalware [Trj]), ESET-NOD32 (Android/Spy.Agent.FLV Trojan), Kaspersky (HEUR:Trojan-Spy.AndroidOS.Agent.avg), and Combo Cleaner (Android.Riskware.Agent.gHXKW). The campaign operates within the broader context of the February-March 2026 U.S.-Israel-Iran conflict escalation, with Unit 42 and CloudSEK documenting approximately 60 hacktivist groups becoming active following the February 28 kinetic strikes. Medium-confidence attribution to Arid Viper (APT-C-23) is supported by the group's established pattern of Android trojanization documented in ESET's June 2024 AridSpy research (five campaigns since 2022, three still active), Cisco Talos mobile spyware reporting, and SentinelOne's SpyC23 analysis. The campaign represents a direct tactical evolution from the October 2023 Red Alert exploitation documented by Cloudflare Cloudforce One. As of March 12, 2026, no takedown of the ra-backup[.]com C2 domain has been confirmed, and the campaign is assessed as still active with researchers expecting escalation alongside the ongoing conflict.
MITRE ATT&CK techniques used in TL-2026-0192
Defense Evasion
T1406 Obfuscated Files or Information; T1407 Download New Code at Runtime; T1630 Indicator Removal on Host; T1632 Subvert Trust Controls; T1655 Masquerading
Credential Access
Discovery
T1418 Software Discovery; T1426 System Information Discovery
Collection
T1430 Location Tracking; T1533 Data from Local System; T1636 Protected User Data
Command and Control
T1437 Application Layer Protocol
Persistence
T1624 Event Triggered Execution
Exfiltration
T1646 Exfiltration Over C2 Channel
Initial Access
Affected products and versions in Trojanized Red Alert Rocket Warning App
- N/A (Trojanized third-party app) — Red Alert / Oref Alert (Trojanized)
Vulnerable versions: com.red.alertx (all versions)
Fixed in: Official app from Google Play Store - Google — Android
Vulnerable versions: All versions (legacy and modern API levels)
Remediation for Trojanized Red Alert Rocket Warning App
Immediate actions
- Block ra-backup.com and api.ra-backup.com at DNS and firewall level
- Block IP addresses 44.208.242.141, 44.200.176.254, and 216.45.58.148 at network perimeter
- Alert users to delete any app with package name com.red.alertx immediately
- Monitor network traffic for connections to api.ra-backup.com/analytics/submit.php
- Block bit.ly shortened URLs in SMS messages referencing emergency app updates
Workarounds
- Perform full factory reset of any device that installed the trojanized app
- Revoke and rotate credentials for all accounts on compromised devices (Google, email, banking, messaging)
- Install Red Alert only from the official Google Play Store listing
- Reject permission requests from emergency apps beyond notification access
Longer-term hardening
- Deploy mobile threat defense (MTD) solutions capable of detecting sideloaded APKs with spoofed signatures
- Implement SMS filtering to detect phishing messages impersonating government agencies
- Enforce Google Play Protect on all managed Android devices
- Conduct user awareness training on sideloading risks during conflict periods
- Monitor for Arid Viper TTPs across mobile device fleet
Weaknesses (CWE) in Trojanized Red Alert Rocket Warning App
Timeline of Trojanized Red Alert Rocket Warning App
- Prior Red Alert trojanization campaign observed, attributed to hacktivist group AnonGhost during October 2023 conflict escalation
- C2 domain ra-backup[.]com registered via Namecheap Inc., indicating operational preparation began at least 8 months before campaign launch [Source: https://www.acronis.com/en/tru/posts/mobile-spyware-campaign-impersonates-israels-red-alert-rocket-warning-system/]
- C2 domain ra-backup.com registered via Namecheap, indicating attacker infrastructure preparation approximately 8 months before campaign launch
- U.S. and Israel launch coordinated strikes on Iranian targets under Operations Roaring Lion and Epic Fury, triggering surge in retaliatory cyber operations from Iran-aligned and Hamas-aligned groups [Source: https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/]
- Israeli citizens post screenshots of suspicious rocket-alert SMS messages on social media; Acronis TRU discovers the campaign; malicious APK first submitted to VirusTotal (3/65 initial detections at 12:44:22 UTC) [Source: https://www.acronis.com/en/tru/posts/mobile-spyware-campaign-impersonates-israels-red-alert-rocket-warning-system/]
- Trojanized RedAlert.apk submitted to VirusTotal achieving only 3/65 detections; Acronis TRU discovers campaign; multiple Israeli citizens report suspicious SMS messages on social media
- Acronis TRU completes full static and dynamic analysis of the trojanized RedAlert APK, documenting multi-stage loader, certificate spoofing, and geofencing capabilities [Source: https://www.acronis.com/en/tru/posts/mobile-spyware-campaign-impersonates-israels-red-alert-rocket-warning-system/]
- Acronis TRU completes full reverse engineering of the multi-stage APK loader, spyware module, and C2 infrastructure
- Infosecurity Magazine publishes initial coverage of the RedAlert spyware campaign, documenting wartime exploitation vector and Arid Viper attribution assessment [Source: https://www.infosecurity-magazine.com/news/redalert-israel-spyware-campaign/]
- CloudSEK publishes independent technical analysis confirming multi-stage infection chain (loader, umgdn asset, DebugProbesKt.dex), documents 5 C2/infrastructure IPs and 4 distribution URLs; The National reports on Israeli government warnings [Source: https://www.cloudsek.com/blog/redalert-trojan-campaign-fake-emergency-alert-app-spread-via-sms-spoofing-israeli-home-front-command]
- CloudSEK publishes independent analysis confirming IOCs and identifying additional infrastructure including distribution URLs and staging domains
- Acronis TRU publishes full technical blog post with detailed MITRE ATT&CK mapping (11 techniques), IOCs, and attribution analysis; The Register publishes coverage noting Israeli National Cyber Directorate warning and quoting TRU researcher Eliad Kimhy on unknown infection scope [Source: https://www.theregister.com/2026/03/06/spyware_disguised_as_emergency_alert/]
- Acronis TRU publishes full report; Israeli National Cyber Directorate and major Israeli news outlets issue public warnings; widespread media coverage across The Register, Infosecurity Magazine, SC Media, and others
- Hackread publishes analysis linking campaign to broader geopolitical exploitation pattern alongside January 2026 Mustang Panda/LOTUSLITE (Venezuela) and February 2026 Crescent Harvest (Iran) campaigns [Source: https://hackread.com/hackers-fake-red-alert-rocket-alert-app-spy-israel-users/]
- Campaign remains active with ongoing SMS distribution; monitoring continues for new infrastructure and variant APKs
- RedPacket Security publishes coverage confirming Israeli National Cyber Directorate and major Israeli news sites issued warnings; PCRisk publishes malware removal guide with AV detection names [Source: https://www.redpacketsecurity.com/spyware-disguised-as-emergency-alert-app-sent-to-israeli-smartphones/]
- GBHackers and CyberPress publish updated technical analyses; Infosecurity Magazine article updated; Virus Bulletin posts advisory on X/Twitter; campaign assessed as still active [Source: https://gbhackers.com/trojanized-red-alert-app/]
- As of 2026-05-29, the Arid Viper (APT-C-23) trojanized Red Alert smishing campaign appears to have wound down active distribution—its C2 (api.ra-backup.com) now returns 404 and INCD/media issued warnings—but no confirmed takedown occurred. The Hamas-aligned actor remains operational with multiple AridSpy campaigns still active, so the threat persists (no CVE; KEV N/A).
Sources cited for Trojanized Red Alert Rocket Warning App
- Acronis TRU: Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
- CloudSEK: RedAlert Trojan Campaign — Fake Emergency Alert App Spread via SMS Spoofing
- The Register: Spyware disguised as emergency-alert app sent to Israelis
- Infosecurity Magazine: RedAlert Spyware Campaign Exploits Wartime Panic With Trojanized App
- CybersecurityNews: RedAlert Mobile Espionage Campaign Targets Civilians
- Hackread: Hackers Spread Fake Red Alert Rocket Alert App to Spy on Israeli Users
- SC Media: Trojanized Israeli rocket warning app spread in cyberespionage campaign
- GBHackers: RedAlert Mobile Espionage Campaign Exploits Trojanized Rocket Alert App
- Cloudflare: Malicious RedAlert Rocket Alerts Application (2023 campaign)
- MITRE ATT&CK: Arid Viper (G1028)
Detection coverage for TL-2026-0192
As of 2026-03-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0192 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.