DCHSpy
MITRE ATT&CK: S1243 View on attack.mitre.org
Aliases: DCHSpy
- First seen
- 2023-03-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 14:05:42
Targeted industries: government-and-public-sector financial-services
Targeted regions: country_code:ir country_code:iq country_code:sa
Context
DCHSpy is an Android spyware likely used by MuddyWater. DCHSpy uses political decoys and masquerades as legitimate applications, such as VPNs and banking applications, to trick victims into downloading the malware. Once downloaded, DCHSpy collects information from the device and exfiltrates the data to the command and control (C2) server.
Malware & tools used
- Contact List (attack-pattern)
- Video Capture (attack-pattern)
- Location Tracking (attack-pattern)
- Audio Capture (attack-pattern)
- SMS Messages (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Stored Application Data (attack-pattern)
- Archive Collected Data (attack-pattern)
- Accounts (attack-pattern)
- Call Log (attack-pattern)
- Data from Local System (attack-pattern)
- Match Legitimate Name or Location (attack-pattern)
Used by threat actors
- MuddyWater (threat-actor)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Dchspy (report)
- shindan.io — Dhcspy Discovering The Iranian Apt Muddywater (report)
- lookout.com — Lookout Discovers Iranian Dchsy Surveillanceware (report)
- MITRE ATT&CK — S1243 (report)