TF-MAL-apk.dhcspy
📛 Threat Title
Malware family: DHCSpy
Description
ThreatFox malware family `apk.dhcspy`. Printable name: DHCSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.dhcspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dhcspy
IOC database
- Type
- domain
- Value
apk.dhcspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.dhcspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dhcspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arxiv.org
As part of ongoing research and future directions, Section VI explores the application of PU/NU learning techniques to the detection of TunnelVision attacks, offering new perspectives on automated detection and mitigation strategies for DHCP-related security threats.
-
web:cybersecuritynews.com
The malware systematically harvests accounts logged into infected devices, contacts, SMS messages, files stored locally, precise location data, and complete call logs. Most concerningly, it can record audio by seizing control of device microphones and capture photos through camera manipulation.
-
web:ieeexplore.ieee.org
The evolution of IoT malware has ignited interest in the creation of malware family classification models. Nonetheless, these models encounter security concerns stemming from issues related to their interpretability and vulnerabilities exposed within the training pipeline. Recent research highlighted the limitations of learning-based malware classifiers, which are susceptible to backdoor ...
-
web:shindan.io
Randorisec - Shindan Authors: Paul (R3dy) Viard In this article, we will deep dive into internals works and key components of a new sample of the DHCSpy Android spyware family , discovered by Lookout after the start of the Israel-Iran conflict. This malware is developed and maintained by an Iranian APT : MuddyWater. According to MITRE ATT&CK: MuddyWater is a cyber espionage group assessed to be ...
-
web:thehackernews.com
DCHSpy also shares infrastructure with another Android malware known as SandStrike, which was flagged by Kaspersky in November 2022 as targeting Persian-speaking individuals by posing as seemingly harmless VPN applications.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.infosecurity-magazine.com
DCHSpy is an Android surveillanceware family that has been active since at least 2024. It shares infrastructure with another Android malware known as SandStrike, an Android surveillance tool first reported by Kaspersky in 2022 targeting practitioners of the Baháʼí Faith, a religion practiced in Iran and parts of the Middle East.
-
web:www.linkedin.com
🚨 New blog post - DHCSpy : Discovering the Iranian APT MuddyWater In this article, Paul V., research apprentice at Shindan, breaks down the newly Android spyware DHCSpy , operated by the ...
-
web:www.lookout.com
Lookout discovered four new samples of DCHSpy one week after the start of the Israel-Iran conflict. DCHSpy is an Android surveillanceware tool leveraged by Iranian cyber espionage group MuddyWater. DCHSpy collects WhatsApp data, accounts, contacts, SMS, files, location, and call logs, and can record audio and take photos. It appears that new targeting could be using lures centered around ...
-
web:www.securityweek.com
Iranian APT MuddyWater has been using new versions of the DCHSpy Android surveillance tool since the beginning of the conflict with Israel.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.