Randorisec researcher Paul Viard published a deep-dive analysis on Randorisec into the DHCSpy Android spyware family — malware developed and maintained by MuddyWater, an Iranian APT assessed by MITRE ATT&CK as a subordinate element of Iran's Ministry of Intelligence and Security (MOIS). The analyzed sample, distributed as "Earth VPN" from hxxps://www[.]earthvpn[.]org, is built on modified open-source OpenVPN code, disguising the spyware as a functional VPN application that automatically executes malicious background collection routines whenever the victim activates the VPN.
DHCSpy Family: Four VPN-Themed Variants Since 2022
DHCSpy was first discovered by Lookout on July 16, 2023, identified as "Hide VPN." Subsequent variants from the same family include Hazrat Eshq, Earth VPN, and Comodo VPN — all using VPN application branding to deceive victims. Development traces recovered from a Comodo VPN sample's C2 test response indicate the malware has been in active development since August 10, 2022. The Earth VPN variant carries package name com.earth.earth_vpn (versionName: 1.3.0, versionCode: 4), with the earliest known Earth VPN sample dated July 20, 2025 though Wayback Machine archives confirm the distribution site was active from at least March 2024. A developer identifier "hossein" was recovered from compilation traces in APK library artifacts.
Operational Design: OpenVPN Trojanization for Automatic Background Execution
DHCSpy's core evasion strategy is embedding its surveillance routines within a working VPN application. By modifying open-source OpenVPN code, the malware activates automatically each time the victim enables the VPN — framing all malicious background activity as expected VPN behavior. Once active, the spyware collects WhatsApp files, device contact lists, videos, and additional sensitive data from the infected device. The VPN functionality remains intact from the user's perspective, reducing suspicion and extending dwell time.
MuddyWater: MOIS-Linked APT with Broad Sectoral and Geographic Targeting
MuddyWater has been active since at least 2017, targeting government and private organizations across telecommunications, local government, defense, and oil and natural gas sectors in the Middle East, Asia, Africa, Europe, and North America. The DHCSpy Android spyware family represents the group's mobile surveillance capability, likely deployed against targets where desktop-focused intrusion tooling is less effective or where mobile device access to communications and personal data provides higher intelligence value. The Israel-Iran conflict context of Lookout's initial discovery aligns with MuddyWater's history of geopolitically motivated surveillance operations against regional adversaries and affiliated organizations.