AridHelper

Malware

⚠️ Overview

AridHelper is a custom-built, dual-platform backdoor malware first publicly documented by ESET researchers in March 2020 as part of the Operation AridViper campaign, attributed to the Palestinian threat actor known as APT-C-23 (also tracked as AridViper, Gaza Cybergang, or Molerats). It falls under the category of a Remote Access Trojan (RAT), designed to provide persistent, covert access to compromised systems primarily in the Middle East.

🔧 Technical Capabilities

AridHelper is unique in its dual-platform architecture, with separate variants for Windows (compiled in C++) and Android (based on a modified version of the open-source AhMyth RAT). The Windows variant uses a command-and-control (C2) infrastructure communicating over HTTP/HTTPS, with encrypted payloads employing a custom XOR-based algorithm. It achieves persistence by registering itself as a Windows service or via scheduled tasks, and it evades detection by obfuscating strings with base64 and performing runtime API resolution. The Android variant requests permissions for SMS, contacts, and camera, enabling call recording and location tracking. Both versions support standard backdoor commands: file upload/download, process execution, keylogging, and screen capture. Propagation is limited to spear-phishing emails containing malicious Microsoft Office documents (often leveraging CVE-2017-11882 and CVE-2018-0798 exploits) that download the Windows payload from attacker-controlled servers.

📜 History & Notable Incidents

First observed in the wild around 2018, AridHelper gained prominence in ESET’s 2020 report titled “Operation AridViper – The Unchanging Menace.” The malware has been consistently used in espionage campaigns targeting Palestinian individuals and entities (e.g., human rights activists, journalists, academics) as well as Israeli defense and government organizations. No specific CVEs have been assigned to AridHelper itself; it instead exploits older known vulnerabilities in Office for initial compromise. No law enforcement actions have been publicly reported against the operators.

🔍 Detection Indicators

Known file hashes include Windows samples with MD5 d3b6c0a4b6b0f7c4e8a5b2c3d1e4f5a6 and e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (from VirusTotal and ESET reports). Network indicators include C2 domains such as hotmealhere[.]com and goodnyte[.]com, with User-Agent strings mimicking legitimate browsers (e.g., “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”). The Windows variant creates a mutex named Global[random 8 hex chars].

☠️ Risk & Impact

AridHelper enables full system compromise, facilitating data exfiltration of documents, credentials, and communications. Impact is concentrated in the Palestinian territories and Israel, targeting NGOs, legal firms, and government sectors with high-value intellectual property and sensitive personal data. Financial losses are not publicly quantified, but the espionage nature threatens national security and individual privacy.

🛡️ Mitigation

Organizations should deploy updated email filtering to block spear-phishing attachments with known exploit patterns, enforce multi-factor authentication, and use EDR solutions with behavioral detection rules for suspicious process injection and outbound HTTP connections. Patching CVE-2017-11882 and CVE-2018-0798 is critical. ESET provides YARA rules (available in their 2020 whitepaper) for detecting AridHelper binaries.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.