Cybersecurity researchers are raising the alarm over a new and highly sophisticated spyware tool , DCHSpy ,which is being distributed disguised as VPN and Starlink apps for Android. According to , Lookoutthe spyware is allegedly linked to the MuddyWater, a known Iranian APT group associated with Iran’s Ministry of Intelligence and Security (MOIS).

DCHSpy activity was detected just days after the start of the Iran-Israel conflict last month, fueling suspicions that the tool is being used in targeted espionage operations against dissidents, journalists, activists, and other “undesirable” users for the regime.
See also: Russian hackers use new Authentic Antics malware
Spyware disguised as Starlink service and VPN apps
The DCHSpy spyware is distributed via fake APK files, such as the app named “starlink_vpn(1.3.0)-3012(1).apk”, which attempts to capitalize on the increased interest in SpaceX’s satellite connection. It is worth noting that Starlink was recently activated in Iran during a blackout, which likely makes it easy bait for users looking for alternative sources of internet access. However, the country’s parliament has now voted to ban its use due to unauthorized operations.
Variants of the spyware also mimic legitimate services such as Earth VPN, Comodo VPN , and Hide VPN, creating the illusion of legitimate tools that provide security and anonymity. In reality, users download a modular trojan that has the ability to monitor:
- Contacts, SMS and files
- Device location
- Accounts and credentials
- Call logs and WhatsApp activity
- Audio and video via microphone and camera
Targeted attacks via Telegram and Phishing
Lookout notes that DCHSpy is primarily distributed via Telegram, leveraging malicious links that are pushed directly to victims. The baits are based on political or social themes, often related to opposition groups or VPNs that bypass state censorship. Early samples primarily targeted English- and Persian-speaking users, fueling the theory of targeted surveillance campaigns.
See also: Batavia spyware targets businesses in Russia
This malware shares infrastructure with SandStrike, another Iranian spyware detected by Kaspersky in 2022, and had similar characteristics and infection tactics. The existence of commonalities between DCHSpy and SandStrike suggests the continuation and evolution of a broader state-sponsored digital espionage program.

Political background and geopolitical dimension of cyberespionage
DCHSpy is not just another Android spyware. Rather, it is part of a growing wave of targeted cyberattacks with a geopolitical undertone, particularly in the wake of the escalation of tensions between Iran and Israel. The use of spyware of this kind, especially under the guise of VPN applications, demonstrates the strategic targeting of sensitive groups – such as journalists, political activists, and members of the diaspora – with tools that initially offer a sense of security.
The DCHSpy case joins other recorded threats that have targeted the Middle East recently (e.g. AridSpy, GuardZoo, BouldSpy, SpyNote and RatMilad).
What users can do to protect themselves
Android users should be especially cautious with apps that come from outside the Google Play Store, especially when it comes to VPN services or apps that promise “anonymous access” or “unblocking the internet.”
Recommendations:
- Do not install APKs from unofficial sources.
- Use trusted VPN apps that are verified by security organizations.
- Enable security settings like Google Play Protect.
- Check the permissions that apps request – especially when it comes to microphones, cameras, or location data.
See also: Android spyware Catwatchful leaks 62,000 user logins
The discovery of DCHSpy highlights the complexity and nature of modern digital espionage. The ability of spyware to disguise itself as a VPN or Starlink app, and target users in politically charged environments, confirms the transition from “random malware” to targeted, nationally orchestrated operations with long-term goals.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
