SandStrike is an Android spyware family linked in the provided reporting to the Iran-aligned threat group MuddyWater, which has been tied by USCYBERCOM to Iran’s Ministry of Intelligence and Security (MOIS). It was reported by Kaspersky in November 2022 as targeting Persian-speaking individuals while masquerading as seemingly benign VPN applications. Lookout states that newer MuddyWater Android spyware tracked as DCHSpy shares tactics and infrastructure with SandStrike, and specifically notes reuse of infrastructure between the two. In the cited analysis, a SandStrike sample contained a malicious VPN configuration file tied to threat-actor-controlled infrastructure, and a hardcoded C2 IP address in a SandStrike sample was also reportedly used multiple times to deploy a MuddyWater-attributed PowerShell RAT. Based on the content, SandStrike is associated with mobile surveillance activity targeting individuals in the Middle East, particularly Persian-speaking users, using fake VPN-themed lures and messaging-app-based delivery patterns similar to those later seen with DCHSpy. No direct SandStrike-specific capabilities beyond its classification as Android spyware and its VPN-themed masquerading are explicitly described in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"DCHSpy uses similar tactics and infrastructure as SandStrike."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that targets Persian-speaking individuals and is distributed by masquerading as benign VPN applications; shares tactics and infrastructure with DCHSpy.
Referenced as related malware sharing tactics/infrastructure with DCHSpy; Lookout notes a SandStrike sample used a hardcoded C2 IP also used to deploy a MuddyWater-attributed PowerShell RAT and contained a malicious VPN configuration tied to actor-controlled infrastructure.
Android spyware linked to MuddyWater; observed containing a malicious VPN configuration that connects to MuddyWater infrastructure and used to deploy a MuddyWater PowerShell RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.