TF-MAL-apk.dchspy
📛 Threat Title
Malware family: DCHSpy
Description
ThreatFox malware family `apk.dchspy`. Printable name: DCHSpy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.dchspy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dchspy
IOC database
- Type
- domain
- Value
apk.dchspy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.dchspy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dchspy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybernews.com
Security researchers from cybersecurity firm Lookout have found new versions of DCHSpy disguised as authentic VPNs or banking applications. DCHSpy is Android spyware developed and maintained by MuddyWater, a cyber espionage group believed to be affiliated with Iran's Ministry of Intelligence and Security. According to Lookout, this group has targeted numerous government and private entities ...
-
web:cybersecuritynews.com
The malware demonstrates continued development and sophistication, indicating sustained investment by state-sponsored actors in mobile surveillance capabilities. Technical analysis reveals that DCHSpy shares infrastructure with another Android malware known as SandStrike, which previously targeted Baháʼí practitioners.
-
web:cybershafarat.com
In late June 2025, about a week after Israeli airstrikes struck Iran's nuclear facilities, cybersecurity researchers uncovered a stealthy new threat on Iranian dissidents' Android phones. Four new samples of the espionage malware known as DCHSpy have surfaced, disguised as innocuous VPN apps named Earth VPN and Comodo VPN. One tainted app even carried "Starlink"…
-
web:gbhackers.com
Security researchers at Lookout have identified four novel samples of DCHSpy , an advanced Android surveillanceware attributed.
-
web:thehackernews.com
DCHSpy Android spyware, linked to Iran's MOIS, mimics VPN and Starlink apps to spy on dissidents.
-
web:www.broadcom.com
A new campaign distributing mobile DCHSpy surveillanceware malware has been reported in the wild. The activity is attributed to the Seedworm APT group (aka MuddyWater). DCHSpy has the functionality to collect and exfiltrate various data from the compromised devices including: stored contacts, SMS messages, local files, call logs, WhatsApp messenger data and more. The malware has also ...
-
web:www.infosecurity-magazine.com
DCHSpy is an Android surveillanceware family that has been active since at least 2024. It shares infrastructure with another Android malware known as SandStrike, an Android surveillance tool first reported by Kaspersky in 2022 targeting practitioners of the Baháʼí Faith, a religion practiced in Iran and parts of the Middle East.
-
web:www.lookout.com
Lookout discovered four new samples of DCHSpy one week after the start of the Israel-Iran conflict. DCHSpy is an Android surveillanceware tool leveraged by Iranian cyber espionage group MuddyWater. DCHSpy collects WhatsApp data, accounts, contacts, SMS, files, location, and call logs, and can record audio and take photos. It appears that new targeting could be using lures centered around ...
-
web:www.securityweek.com
Malware & Threats Iranian APT Targets Android Users With New Variants of DCHSpy Spyware Iranian APT MuddyWater has been using new versions of the DCHSpy Android surveillance tool since the beginning of the conflict with Israel.
-
web:zahidaz.github.io
DCHSpy is an Iranian Android surveillanceware operated by MuddyWater, an espionage group linked to Iran's Ministry of Intelligence and Security (MOIS). Lookout discovered DCHSpy in July 2025, identifying 11 samples dating back to 2021. The malware is distributed through fake VPN apps (Earth VPN, Comodo VPN, Hide VPN) and StarLink connectivity lures, exploiting Iranian internet outages to ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.