DCHSpy

MITRE ATT&CK: S1243 View on attack.mitre.org

Aliases: DCHSpy

First seen
2023-03-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 14:05:42

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:ir country_code:iq country_code:sa

Context

DCHSpy is an Android spyware likely used by MuddyWater. DCHSpy uses political decoys and masquerades as legitimate applications, such as VPNs and banking applications, to trick victims into downloading the malware. Once downloaded, DCHSpy collects information from the device and exfiltrates the data to the command and control (C2) server.

Malware & tools used

  • Contact List (attack-pattern)
  • Video Capture (attack-pattern)
  • Location Tracking (attack-pattern)
  • Audio Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Application Layer Protocol (attack-pattern)
  • Stored Application Data (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Accounts (attack-pattern)
  • Call Log (attack-pattern)
  • Data from Local System (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)

Used by threat actors

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Dchspy (report)
  • shindan.io — Dhcspy Discovering The Iranian Apt Muddywater (report)
  • lookout.com — Lookout Discovers Iranian Dchsy Surveillanceware (report)
  • MITRE ATT&CK — S1243 (report)

External references