{"id":27422,"date":"2025-07-22T01:10:15","date_gmt":"2025-07-22T01:10:15","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/27422\/"},"modified":"2025-07-22T01:10:15","modified_gmt":"2025-07-22T01:10:15","slug":"spyware-uses-starlink-name-to-trick-iranians-desperate-for-unfiltered-internet","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/27422\/","title":{"rendered":"Spyware Uses Starlink Name to Trick Iranians Desperate for Unfiltered Internet"},"content":{"rendered":"<p>An Android-based <a href=\"https:\/\/www.pcmag.com\/picks\/the-best-spyware-protection-security-software\" target=\"_self\" rel=\"nofollow noopener\">spyware<\/a> program is using the Starlink name to trick Iran-based web users into installing it, according to researchers at cybersecurity vendor <a href=\"https:\/\/www.lookout.com\/\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">Lookout<\/a>.<\/p>\n<p>The company has linked the spyware program, dubbed DCHSpy, to the Iranian state-sponsored group <a href=\"https:\/\/www.cybercom.mil\/Media\/News\/Article\/2897570\/iranian-intel-cyber-suite-of-malware-uses-open-source-tools\/\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">MuddyWater<\/a>, a unit that allegedly works in Iran&#8217;s Ministry of Intelligence and Security,  citing internet domains that match earlier spyware attacks tied to the group. The spyware can steal data such as call logs, location data, and SMS messages, take photos and record audio.<\/p>\n<p>Although the spyware was <a href=\"https:\/\/www.lookout.com\/threat-intelligence\/report\/q2-2024-mobile-landscape-threat-report\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">flagged<\/a> last year, Lookout spotted new versions of DCHSpy posing as <a href=\"https:\/\/www.pcmag.com\/picks\/the-best-vpn-services\" target=\"_self\" rel=\"nofollow noopener\">VPN<\/a> apps. Following Israeli and US bombing campaigns on Iran, the country restricted access to the internet to thwart Israeli cyberattacks and quash dissent. VPN usage then <a href=\"https:\/\/www.pcmag.com\/news\/vpn-use-in-iran-spikes-700-amid-internet-restrictions\" target=\"_self\" rel=\"nofollow noopener\">surged<\/a>.<\/p>\n<p><img decoding=\"async\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" class=\"\" data-image-loader=\"https:\/\/i.pcmag.com\/imagery\/articles\/00vvUiQETMTr2Aphsgmit9u-2.png\" data-lazy-sized=\"\" alt=\"The spyware samples\" data-image-path=\"articles\/00vvUiQETMTr2Aphsgmit9u-2.png\"\/><\/p>\n<p>\n    (Credit: Lookout)\n<\/p>\n<p>The four recovered spyware samples used the names \u201cEarth VPN\u201d and \u201cComodo VPN\u201d to phish users looking for access to uncensored internet.<\/p>\n<p>While examining the spyware samples, Lookout also uncovered the use of the Starlink name. \u201cOne of the Earth VPN samples, SHA1:9dec46d71289710cd09582d840177180547f438, was uploaded with an APK filename of starlink _ vpn(1.3.0)-3012 (1).apk,\u201d the company said. \u201cThis may indicate that DCHSpy VPN samples are also being spread with Starlink lures, especially given recent reports of Starlink offering internet services to the Iranian population during the internet outage imposed by the Iranian government following hostilities between Israel and Iran.\u201d<\/p>\n<p>Since 2022, SpaceX has enabled Starlink access in Iran, despite the government\u2019s protests. Local Iranian residents have <a href=\"https:\/\/www.pcmag.com\/news\/dozens-of-starlink-dishes-are-being-smuggled-into-iran\" target=\"_self\" rel=\"nofollow noopener\">smuggled<\/a> the satellite internet hardware into the country, with one group <a href=\"https:\/\/www.iranintl.com\/en\/202501060034\" target=\"_blank\" title=\"(Opens in a new tab)\" rel=\"nofollow noopener\">estimating<\/a> that Iran has over 100,000 Starlink users.<\/p>\n<p>        Recommended by Our Editors<\/p>\n<p><img decoding=\"async\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" http:=\"\" class=\"\" data-image-loader=\"https:\/\/i.pcmag.com\/imagery\/articles\/00vvUiQETMTr2Aphsgmit9u-3.jpg\" data-lazy-sized=\"\" alt=\"Starlink dish\" data-image-path=\"articles\/00vvUiQETMTr2Aphsgmit9u-3.jpg\"\/><\/p>\n<p>\n    (Photo by Anonymous\/Middle East Images\/AFP via Getty Images)\n<\/p>\n<p>In Iran, the satellite internet service stands out by providing internet access without government-imposed censorship. It looks like MuddyWater is trying to exploit the Starlink name to phish users desperate for that unfiltered broadband access. Lookout notes DCHSpy has been circulating through <a href=\"https:\/\/www.pcmag.com\/picks\/best-secure-messaging-apps\" target=\"_self\" rel=\"nofollow noopener\">messaging apps<\/a> such as <a href=\"https:\/\/www.pcmag.com\/reviews\/telegram\" target=\"_self\" rel=\"nofollow noopener\">Telegram<\/a>.\u00a0<\/p>\n<p>\u201cThese new samples show that MuddyWater has continued to develop the surveillanceware with new capabilities\u2014this time exhibiting the ability to identify and exfiltrate data from files of interest on the device as well as WhatsApp data,\u201d the cybersecurity vendor added.\u00a0<\/p>\n<p>                                <img decoding=\"async\" class=\"w-full\" src=\"https:\/\/cdn.ex.co\/transformations\/production\/82855de7-16c2-4158-82a7-fc3fae280f1e\/thumbnail-720.webp\" alt=\"5 Things to Know About Starlink Satellite Internet\"\/><\/p>\n<p>                    <img decoding=\"async\" class=\"max-w-[2.5rem] md:min-w-12 md:max-w-12\" src=\"https:\/\/www.pcmag.com\/images\/pcmag.svg\" alt=\"PCMag Logo\"\/><\/p>\n<p>5 Things to Know About Starlink Satellite Internet<\/p>\n<p>        <img decoding=\"async\" class=\"opacity-20 absolute right-0 top-0 z-0 hidden md:block\" src=\"https:\/\/www.pcmag.com\/images\/newsletter-envelope.svg\" alt=\"Newsletter Icon\" style=\"max-width:220px; max-height:140px; pointer-events:none;\"\/><\/p>\n<p>            <img decoding=\"async\" class=\"opacity-20 h-full w-full\" src=\"https:\/\/www.pcmag.com\/images\/newsletter-envelope.svg\" alt=\"Newsletter Icon\"\/><\/p>\n<p>\n            Get Our Best Stories!\n        <\/p>\n<p>                                    Stay Safe With the Latest Security News and Updates<\/p>\n<p>                                                    <img decoding=\"async\" class=\"h-auto w-full rounded-md object-cover md:rounded-l-md\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/07\/17707707-contextual.fit_lpad.size_250x140.v1750711966.png\" alt=\"SecurityWatch Newsletter Image\"\/><\/p>\n<p>Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.<\/p>\n<p>Sign up for our SecurityWatch newsletter for our most important privacy and security stories delivered right to your inbox.<\/p>\n<p class=\"roboto-flex mt-2 text-xs font-normal leading-tight text-black md:whitespace-nowrap\">\n                        By clicking Sign Me Up, you confirm you are 16+ and agree to our <a class=\"underline\" href=\"https:\/\/www.pcmag.com\/terms\" rel=\"nofollow noopener\" target=\"_blank\">Terms of Use<\/a> and <a class=\"underline\" href=\"https:\/\/www.pcmag.com\/privacy\" rel=\"nofollow noopener\" target=\"_blank\">Privacy Policy<\/a>.\n                    <\/p>\n<p class=\"text-green-500 mt-2 text-xl font-bold\">Thanks for signing up!<\/p>\n<p class=\"mt-2\">Your subscription has been confirmed. Keep an eye on your inbox!<\/p>\n<p>                    About Michael Kan<\/p>\n<p>\n                            Senior Reporter\n                        <\/p>\n<p>                            <img decoding=\"async\" class=\"w-full rounded-full\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/07\/06W4G6A5rmg4LxEffqKnnc6.fit_lim.size_200x200.v1560221550.png\" alt=\"Michael Kan\" width=\"90px\" height=\"90px\" loading=\"lazy\"\/><\/p>\n<p>I&#8217;ve been working as a journalist for over 15 years\u2014I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017.<\/p>\n<p>\n                            <a class=\"font-bold\" href=\"https:\/\/www.pcmag.com\/authors\/michael-kan\" aria-label=\"Michael&#039;s Author Bio\" rel=\"nofollow noopener\" target=\"_blank\"><br \/>\n                                Read Michael&#8217;s full bio<br \/>\n                            <\/a>\n                        <\/p>\n<p>                                    Read the latest from Michael Kan<\/p>\n","protected":false},"excerpt":{"rendered":"An Android-based spyware program is using the Starlink name to trick Iran-based web users into installing it, according&hellip;\n","protected":false},"author":2,"featured_media":27423,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43],"tags":[174,74],"class_list":{"0":"post-27422","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-internet","8":"tag-internet","9":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/27422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=27422"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/27422\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/27423"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=27422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=27422"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=27422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}