DCHSpy
Malware family · 4 sample(s) · 39 indicator record(s) · 2 signing certificate(s)
About DCHSpy
Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.
Indicators
Detected samples without extractable endpoint (1)
Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| 55e8b2d87f80… | hazrateeshgh.apk | Flutter-built "Hazrate Eshgh" (حضرت عشق) gallery app themed on Mahsa (Jina) Amini - a political lure matching DCHSpy's Telegram distribution to Farsi speakers. SHA-1 listed in Lookout's DCHSpy IoCs; no endpoint is statically extractable from the Flutter build (config fetched at runtime), so this is a code-/hash-level attribution. source | 2024-04-13 |