Beware – Iran-linked fake VPN apps found to spy on Android users
- Researchers found a new spyware campaign mainly targeting Iranian Android VPN users
- DCHSpy is leveraged by the Iranian cyber espionage group MuddyWater, which is thought to have links with Iran’s Ministry of Intelligence and Security
- The campaign started one week after the Israel-Iran conflict began, while VPN demand skyrocketed across the country
Researchers have discovered a new Iran-linked spyware campaign that mostly targets Android VPN users.
The team at security software provider, Lookout, found a new version of DCHSpy, an Android spyware that masquerades as legitimate VPN apps or other applications. This includes Starlink, a satellite internet connection service offered by SpaceX.
The malware campaign, according to experts’ findings, was deployed by the hacking group MuddyWater only a week after the Israel-Iran conflict began – exactly when VPN demand skyrocketed in Iran as citizens looked for ways to bypass new internet restrictions.
DCHSpy 2025 – what are the risk?

As experts explain, DCHSpy is an intrusive piece of software that can collect users’ sensitive information like WhatsApp data, contacts, SMS, files, location, and call logs, while even recording audio and taking photos.
First detected in July 2024, DCHSpy is maintained by MuddyWater hackers, a group thought to have links with Iran’s Ministry of Intelligence and Security.
Experts have now discovered four new samples of DCHSpy.
“These new samples show that MuddyWater has continued to develop the surveillanceware with new capabilities – this time exhibiting the ability to identify and exfiltrate data from files of interest on the device as well as WhatsApp data,” explains Lookout.
Specifically, hackers appear to be using two malicious VPN services, called EarthVPN and ComodoVPN, as a way to spread the malware.
HideVPN was another fake VPN app previously used to deploy DCHSpy.

According to Iranian Information Security Analyst, Azam Jangrevi, the latest findings are a stark reminder of how sophisticated and targeted mobile surveillance has become.
“What’s especially concerning is its use of trusted platforms like Telegram to distribute malicious APKs, often under the guise of tools meant to protect privacy,” Jangrevi told TechRadar.
The risk for Iranians is especially high, considering that, as mentioned earlier, citizens have been increasingly turning to the best VPN apps as the internet becomes increasingly restricted.
How to stay safe
Jangrevi recommends anyone looking to download a new VPN service, or any other application for that matter, to be vigilant.
“Avoid downloading apps from unofficial sources, even if they appear to offer enhanced privacy. Stick to verified app stores, scrutinize app permissions, and use mobile security solutions that can detect threats like DCHSpy,” said Jangrevi.
If you’re in a high-risk region or profession such as journalism or activism, Jangrevi also suggests using hardware-based security keys and encrypted messaging apps vetted by independent researchers.
She said: “This incident underscores the need for greater awareness around mobile threat vectors and the importance of digital hygiene in an increasingly hostile cyber landscape.”
You might also like
Researchers found a new spyware campaign mainly targeting Iranian Android VPN users DCHSpy is leveraged by the Iranian cyber espionage group MuddyWater, which is thought to have links with Iran’s Ministry of Intelligence and Security The campaign started one week after the Israel-Iran conflict began, while VPN demand skyrocketed across…
Recent Posts
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
- NordVPN Coupons and Deals: 77% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023