s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.dchspy

📛 Threat Title

Malware family: DCHSpy

Category: DCHSpy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.dchspy`. Printable name: DCHSpy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.dchspy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dchspy

IOC database

Type
domain
Value
apk.dchspy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.dchspy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.dchspy

References (1)

Remediations (10)

  • web:cybernews.com

    Security researchers from cybersecurity firm Lookout have found new versions of DCHSpy disguised as authentic VPNs or banking applications. DCHSpy is Android spyware developed and maintained by MuddyWater, a cyber espionage group believed to be affiliated with Iran's Ministry of Intelligence and Security. According to Lookout, this group has targeted numerous government and private entities ...

  • web:cybersecuritynews.com

    The malware demonstrates continued development and sophistication, indicating sustained investment by state-sponsored actors in mobile surveillance capabilities. Technical analysis reveals that DCHSpy shares infrastructure with another Android malware known as SandStrike, which previously targeted Baháʼí practitioners.

  • web:cybershafarat.com

    In late June 2025, about a week after Israeli airstrikes struck Iran's nuclear facilities, cybersecurity researchers uncovered a stealthy new threat on Iranian dissidents' Android phones. Four new samples of the espionage malware known as DCHSpy have surfaced, disguised as innocuous VPN apps named Earth VPN and Comodo VPN. One tainted app even carried "Starlink"…

  • web:gbhackers.com

    Security researchers at Lookout have identified four novel samples of DCHSpy , an advanced Android surveillanceware attributed.

  • web:thehackernews.com

    DCHSpy Android spyware, linked to Iran's MOIS, mimics VPN and Starlink apps to spy on dissidents.

  • web:www.broadcom.com

    A new campaign distributing mobile DCHSpy surveillanceware malware has been reported in the wild. The activity is attributed to the Seedworm APT group (aka MuddyWater). DCHSpy has the functionality to collect and exfiltrate various data from the compromised devices including: stored contacts, SMS messages, local files, call logs, WhatsApp messenger data and more. The malware has also ...

  • web:www.infosecurity-magazine.com

    DCHSpy is an Android surveillanceware family that has been active since at least 2024. It shares infrastructure with another Android malware known as SandStrike, an Android surveillance tool first reported by Kaspersky in 2022 targeting practitioners of the Baháʼí Faith, a religion practiced in Iran and parts of the Middle East.

  • web:www.lookout.com

    Lookout discovered four new samples of DCHSpy one week after the start of the Israel-Iran conflict. DCHSpy is an Android surveillanceware tool leveraged by Iranian cyber espionage group MuddyWater. DCHSpy collects WhatsApp data, accounts, contacts, SMS, files, location, and call logs, and can record audio and take photos. It appears that new targeting could be using lures centered around ...

  • web:www.securityweek.com

    Malware & Threats Iranian APT Targets Android Users With New Variants of DCHSpy Spyware Iranian APT MuddyWater has been using new versions of the DCHSpy Android surveillance tool since the beginning of the conflict with Israel.

  • web:zahidaz.github.io

    DCHSpy is an Iranian Android surveillanceware operated by MuddyWater, an espionage group linked to Iran's Ministry of Intelligence and Security (MOIS). Lookout discovered DCHSpy in July 2025, identifying 11 samples dating back to 2021. The malware is distributed through fake VPN apps (Earth VPN, Comodo VPN, Hide VPN) and StarLink connectivity lures, exploiting Iranian internet outages to ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.