DCHSpy is an Android spyware family associated with the Iran-linked threat actor MuddyWater, which has been tied to Iran’s Ministry of Intelligence and Security. Active since at least 2024, it is used for mobile surveillance against targeted individuals, with reporting indicating lures aimed at English- and Farsi-speaking users and likely focus on dissidents, activists, and journalists in the context of regional tensions and internet restrictions.
DCHSpy is a modular surveillance implant for Android devices. Documented collection capabilities include contacts, SMS messages, call logs, device account information, location data, and files stored on the device, including WhatsApp-related data. Reported variants can also access the microphone and camera to record audio and take photos. Collected information is compressed and encrypted using a password supplied by command-and-control infrastructure before being uploaded, including via SFTP, indicating a structured exfiltration workflow.
Observed delivery has relied on social engineering rather than public exploit chains. DCHSpy has been distributed through malicious links shared over Telegram and disguised as VPN or similar utility applications, including politically themed lures and fake services intended to appeal to users seeking censorship circumvention or connectivity during unrest. Reporting also notes tactical and infrastructure overlap with SandStrike, another Android spyware linked to MuddyWater.
The malware’s behavior and targeting are consistent with espionage-oriented mobile surveillance. Its emphasis on harvesting communications, messaging-app content, files, and sensor data makes it suitable for monitoring victims’ personal networks, movements, and conversations on compromised Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"DCHSpy is Android spyware linked to Iran’s MuddyWater APT... Active since 2024, it’s now resurfacing amid regional conflict, often delivered via Telegram links."
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware masquerading as VPN/Starlink apps; linked to Iranian MOIS and used for surveillance of dissidents (per summary).
... DCHSpy ... (v1.0) ...
Mobile malware referenced as collecting account data (account names/types) from compromised devices as part of its collection behavior.
DCHSpy (v1.0)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.