🚨 New blog post – DHCSpy: Discovering the Iranian APT MuddyWater
In this article, @R3dy_malz , research apprentice at Shindan, breaks down the newly Android spyware DHCSpy, operated by the Iranian APT group MuddyWater, including:
- How the malware disguises itself as a VPN app to gain trust.
- The techniques used to exfiltrate WhatsApp database, contacts, and files.
- The dynamic command-and-control infrastructure and update mechanisms.
- Why the ongoing development of DHCSpy signals further capabilities to come.
👉 Link of full analysis available in the comments ⬇️
@lea_linux il se fout juste de la gueule d'une nana qui a dit trouver un malware dans un connecteur RJ45 <-> USB-C alors que c'était un driver legit. Just another infosec drama on twitter