Four new Android spyware samples linked to Iran's intel agency
ID: 2844952d-df3c-5cfc-939e-c97148588555
STIX ID: report--2844952d-df3c-5cfc-939e-c97148588555
Feed Name: The Register (Security)
Lookout researchers identified four new DCHSpy Android spyware samples linked to Iran's MOIS / MuddyWater, masquerading as VPN apps (Earth VPN, Comodo VPN) and distributed via Telegram and other lures; the malware collects WhatsApp content, audio/video, contacts, SMS, location, call logs and can search for and exfiltrate sensitive files, encrypting and uploading stolen data to attacker-controlled SFTP servers. The discovery indicates active, evolving nation-state surveillance targeting activists, journalists, and dissidents, with recent samples showing expanded capabilities and ongoing usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
