Iran’s Sneaky Spyware: Android Malware Masquerades as VPNs to Hack WhatsApp and More
Iran’s DCHSpy malware, linked to the Ministry of Intelligence and Security, is back in action, this time disguised as VPN apps. It sneaks into devices, collects WhatsApp data, and more. Spotted by Lookout researchers, it’s targeting dissidents and journalists. Remember, if you see a VPN app offering free hugs, think twice!

Hot Take:
Who would have thought that the Iranian Ministry of Intelligence and Security (MOIS) moonlights as a full-fledged spy movie villain, complete with evil mobile apps disguised as friendly VPNs? Just when you thought it was safe to browse the internet, they’re out here channeling their inner James Bond villain—only with a lot less tuxedo and a lot more malware!
Key Points:
– Iranian MOIS-linked Android spyware targets WhatsApp, records audio and video.
– The spyware, dubbed DCHSpy, masquerades as VPN apps like Earth VPN and Comodo VPN.
– Starlink-themed files suggest exploitation of SpaceX internet as a lure.
– MuddyWater group, affiliated with MOIS, is suspected of carrying out the attack.
– New spyware capabilities include collecting WhatsApp data and hunting specific files.