# Trojanized Red Alert Rocket Warning App — Arid Viper Mobile Spyware Campaign Targeting Israeli Users

> A mobile spyware campaign attributed to Arid Viper (APT-C-23) distributes a trojanized version of Israel's Red Alert rocket warning Android application via SMS phishing. The malicious app impersonates the legitimate civil defense app, retaining full alert functionality while exfiltrating SMS messages, contacts, GPS location, and account data to attacker-controlled C2 infrastructure.

- **Published:** 2026-03-07T12:00:00Z
- **Last reviewed:** 2026-03-07T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0192
- **ID:** TL-2026-0192
- **Severity:** HIGH (CVSS 7.5)
- **Category:** MALWARE
- **Status:** MONITORING
- **Actor:** APT-C-23 (Palestine)
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A sophisticated mobile spyware campaign is actively targeting Israeli civilians by distributing a trojanized version of the Red Alert (Oref Alert) rocket warning application for Android. The campaign leverages SMS phishing (smishing) messages that impersonate Israel's Home Front Command, urging recipients to install what appears to be an urgent wartime update to the emergency alert application.

The malicious APK (package name com.red.alertx) employs a multi-stage architecture designed for stealth and persistence. Stage 1 functions as a loader that uses a custom IPackageManagerSignatureProxyLoader to hook the Android PackageManager via dynamic proxy and Java reflection. This proxy intercepts signature verification calls and returns a hardcoded Base64-encoded X.509 certificate (originally issued 2014-07-12, valid until 2114-06-18) that impersonates the legitimate Home Front Command app's signing credential. The loader also forces getInstallerPackageName() to return com.android.vending, making the app appear as though it was installed from the Google Play Store.

Stage 2 extracts a hidden asset file named 'umgdn' from the APK's assets directory. This file contains the legitimate Red Alert application, which is loaded into memory by overwriting Android runtime fields (mAppDir, sourceDir, publicSourceDir). The legitimate app runs in the foreground providing real rocket alerts, while the spyware payload operates silently in the background.

Stage 3 deploys the core spyware module (DebugProbesKt.dex) which requests 20 Android permissions, 6 of which are security-sensitive: ACCESS_FINE_LOCATION (GPS tracking with geofencing), READ_SMS (full SMS database extraction via Telephony.Sms.CONTENT_URI), READ_CONTACTS (contact harvesting with phone numbers and emails), GET_ACCOUNTS (device account enumeration via reflection-based AccountManager invocation), RECEIVE_BOOT_COMPLETED (persistence across reboots), and SYSTEM_ALERT_WINDOW (overlay capability for credential phishing).

The malware employs aggressive obfuscation including Base64-encoded strings with unique 32-byte XOR keys per string, class/method name randomization, trivial wrapper functions to obscure control flow, and runtime reflection for all sensitive API calls. Installed applications are enumerated via PackageManager and exfiltrated in batches of 200.

All harvested data is staged locally and continuously transmitted via HTTPS POST requests to the C2 endpoint at api.ra-backup.com/analytics/submit.php. The C2 domain ra-backup.com was registered on June 23, 2025 through Namecheap, with infrastructure hosted across AWS (44.208.242.141, 44.200.176.254) and fronted by Cloudflare (104.21.64.137, 172.67.137.156).

The campaign was discovered on March 1, 2026 when the APK was submitted to VirusTotal (achieving only 3/65 detections initially) and Israeli citizens began reporting suspicious SMS messages on social media. Acronis Threat Research Unit (TRU) completed full analysis by March 2, and the Israeli National Cyber Directorate issued public warnings by March 6.

Attribution analysis links the campaign to Arid Viper (APT-C-23 / Desert Falcons / Two-tailed Scorpion), a Hamas-aligned cyberespionage group active since at least 2013 with a history of deploying surveillance malware targeting Israeli users across Android, iOS, and Windows platforms. The use of trojanized Android applications, targeting of Israeli civilians, and spyware capabilities are consistent with Arid Viper's established operational patterns. However, researchers note these indicators are not uniquely attributable — a similar 2023 campaign was attributed to hacktivist group AnonGhost.

---

**Revalidated on 2026-03-12**

This threat has been extensively validated through multi-vendor corroboration across at least 10 independent security organizations. The campaign was first detected on March 1, 2026 when Israeli citizens reported suspicious SMS messages on social media, and was independently analyzed by Acronis TRU (primary discoverer), CloudSEK, Palo Alto Unit 42, Infosecurity Magazine, The Register, Hackread, GBHackers, CyberPress, RedPacket Security, and PCRisk. The Israeli National Cyber Directorate issued official warnings. CloudSEK's analysis revealed additional infrastructure details beyond the original reporting: five C2/infrastructure IP addresses (216.45.58.148 on QuadraNet, 44.208.242.141 and 44.200.176.254 on AWS, 104.21.64.137 and 172.67.137.156 on Cloudflare), a third-stage payload (DebugProbesKt.dex) not previously documented in our threat record, and four distribution URLs including compromised WordPress site shirideitch[.]com and three bit.ly shortened links (3Ozydsn, 2O3fHEX, 3GfZoys). AV detection has increased substantially from the initial 3/65 on VirusTotal to broad coverage including Avast (APK:RepMalware [Trj]), ESET-NOD32 (Android/Spy.Agent.FLV Trojan), Kaspersky (HEUR:Trojan-Spy.AndroidOS.Agent.avg), and Combo Cleaner (Android.Riskware.Agent.gHXKW). The campaign operates within the broader context of the February-March 2026 U.S.-Israel-Iran conflict escalation, with Unit 42 and CloudSEK documenting approximately 60 hacktivist groups becoming active following the February 28 kinetic strikes. Medium-confidence attribution to Arid Viper (APT-C-23) is supported by the group's established pattern of Android trojanization documented in ESET's June 2024 AridSpy research (five campaigns since 2022, three still active), Cisco Talos mobile spyware reporting, and SentinelOne's SpyC23 analysis. The campaign represents a direct tactical evolution from the October 2023 Red Alert exploitation documented by Cloudflare Cloudforce One. As of March 12, 2026, no takedown of the ra-backup[.]com C2 domain has been confirmed, and the campaign is assessed as still active with researchers expecting escalation alongside the ongoing conflict.

## MITRE ATT&CK

- T1660 Phishing
- T1624 Event Triggered Execution
- T1655 Masquerading
- T1406 Obfuscated Files or Information
- T1632 Subvert Trust Controls
- T1630 Indicator Removal on Host
- T1407 Download New Code at Runtime
- T1417 Input Capture
- T1418 Software Discovery
- T1426 System Information Discovery
- T1636 Protected User Data
- T1430 Location Tracking
- T1533 Data from Local System
- T1437 Application Layer Protocol
- T1646 Exfiltration Over C2 Channel

## Sources

- [Acronis TRU: Mobile spyware campaign impersonates Israel's Red Alert rocket warning system](https://www.acronis.com/en/tru/posts/mobile-spyware-campaign-impersonates-israels-red-alert-rocket-warning-system/)
- [CloudSEK: RedAlert Trojan Campaign — Fake Emergency Alert App Spread via SMS Spoofing](https://www.cloudsek.com/blog/redalert-trojan-campaign-fake-emergency-alert-app-spread-via-sms-spoofing-israeli-home-front-command)
- [The Register: Spyware disguised as emergency-alert app sent to Israelis](https://www.theregister.com/2026/03/06/spyware_disguised_as_emergency_alert/)
- [Infosecurity Magazine: RedAlert Spyware Campaign Exploits Wartime Panic With Trojanized App](https://www.infosecurity-magazine.com/news/redalert-israel-spyware-campaign/)
- [CybersecurityNews: RedAlert Mobile Espionage Campaign Targets Civilians](https://cybersecuritynews.com/redalert-mobile-espionage-campaign/)
- [Hackread: Hackers Spread Fake Red Alert Rocket Alert App to Spy on Israeli Users](https://hackread.com/hackers-fake-red-alert-rocket-alert-app-spy-israel-users/)
- [SC Media: Trojanized Israeli rocket warning app spread in cyberespionage campaign](https://www.scworld.com/brief/trojanized-israeli-rocket-warning-app-spread-in-cyberespionage-campaign)
- [GBHackers: RedAlert Mobile Espionage Campaign Exploits Trojanized Rocket Alert App](https://gbhackers.com/redalert-mobile-espionage/)
- [Cloudflare: Malicious RedAlert Rocket Alerts Application (2023 campaign)](https://www.cloudflare.com/cloudforce-one/research/malicious-redalert-rocket-alerts-application-targets-israeli-phone-calls-sms-and-user-information/)
- [MITRE ATT&CK: Arid Viper (G1028)](https://attack.mitre.org/groups/G1028/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0192
