Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iran-Linked DCHSpy Android Malware Masquerades as VPN Apps to Spy on Dissidents

Iran-Linked DCHSpy Android Malware Masquerades as VPN Apps to Spy on Dissidents

Posted on July 21, 2025July 21, 2025 By CWS

Jul 21, 2025Ravie LakshmananSpyware / Cellular Safety
Cybersecurity researchers have unearthed new Android spy ware artifacts which can be possible affiliated with the Iranian Ministry of Intelligence and Safety (MOIS) and have been distributed to targets by masquerading as VPN apps and Starlink, a satellite tv for pc web connection service supplied by SpaceX.
Cellular safety vendor Lookout mentioned it found 4 samples of a surveillanceware device it tracks as DCHSpy one week after the onset of the Israel-Iran battle final month. Precisely how many individuals might have put in these apps just isn’t clear.
“DCHSpy collects WhatsApp knowledge, accounts, contacts, SMS, recordsdata, location, and name logs, and might document audio and take photographs,” safety researchers Alemdar Islamoglu and Justin Albrecht mentioned.

First detected in July 2024, DCHSpy is assessed to be the handiwork of MuddyWater, an Iranian nation-state group tied to MOIS. The hacking crew can be referred to as Boggy Serpens, Cobalt Ulster, Earth Vetala, ITG17, Mango Sandstorm (previously Mercury), Seedworm, Static Kitten, TA450, and Yellow Nix.
Early iterations of DCHSPy have been recognized focusing on English and Farsi audio system through Telegram channels utilizing themes that run counter to the Iranian regime. Given using VPN lures to promote the malware, it is possible that dissidents, activists, and journalists are a goal of the exercise.
It is suspected that the newly recognized DCHSpy variants are being deployed towards adversaries within the wake of the current battle within the area by passing them off as seemingly helpful providers like Earth VPN (“com.earth.earth_vpn”), Comodo VPN (“com.comodoapp.comodovpn”), and Disguise VPN (“com.hv.hide_vpn”).

Curiously, one of many Earth VPN app samples has been discovered to be distributed within the type of APK recordsdata utilizing the identify “starlink_vpn(1.3.0)-3012 (1).apk,” indicating that the malware is probably going being unfold to targets utilizing Starlink-related lures.
It is value noting that Starlink’s satellite tv for pc web service was activated in Iran final month amid a government-imposed web blackout. However, weeks later, the nation’s parliament voted to outlaw its use over unauthorized operations.
A modular trojan, DCHSpy is supplied to gather a variety of knowledge, together with account signed-in to the gadget, contacts, SMS messages, name logs, recordsdata, location, ambient audio, photographs, and WhatsApp data.
DCHSpy additionally shares infrastructure with one other Android malware often known as SandStrike, which was flagged by Kaspersky in November 2022 as focusing on Persian-speaking people by posing as seemingly innocent VPN purposes.

The invention of DCHSpy is the most recent occasion of Android spy ware that has been used to focus on people and entities within the Center East. Different documented malware strains embody AridSpy, BouldSpy, GuardZoo, RatMilad, and SpyNote.
“DCHSpy makes use of comparable ways and infrastructure as SandStrike,” Lookout mentioned. “It’s distributed to focused teams and people by leveraging malicious URLs shared straight over messaging apps equivalent to Telegram.”
“These most up-to-date samples of DCHSpy point out continued improvement and utilization of the surveillanceware because the scenario within the Center East evolves, particularly as Iran cracks down on its residents following the ceasefire with Israel.”

The Hacker News Tags:Android, Apps, DCHSpy, Dissidents, IranLinked, Malware, Masquerades, Spy, VPN

Post navigation

Previous Post: China-Linked Hackers Launch Targeted Espionage Campaign on African IT Infrastructure
Next Post: Threat Actors Leverage Zoho WorkDrive Folder to Deliver Obfuscated PureRAT Malware

Related Posts

Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Access The Hacker News
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly The Hacker News
New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally The Hacker News
Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices The Hacker News
Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed The Hacker News
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark