logo

Four new Android spyware samples linked to Iran's intel agency

ID: 2844952d-df3c-5cfc-939e-c97148588555

STIX ID: report--2844952d-df3c-5cfc-939e-c97148588555

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-07-21

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Lookout researchers identified four new DCHSpy Android spyware samples linked to Iran's MOIS / MuddyWater, masquerading as VPN apps (Earth VPN, Comodo VPN) and distributed via Telegram and other lures; the malware collects WhatsApp content, audio/video, contacts, SMS, location, call logs and can search for and exfiltrate sensitive files, encrypting and uploading stolen data to attacker-controlled SFTP servers. The discovery indicates active, evolving nation-state surveillance targeting activists, journalists, and dissidents, with recent samples showing expanded capabilities and ongoing usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.