Open source text editor poisoned with malware to target Uyghur users
ID: d08aa123-158a-593a-a15d-6c9317cd0b7b
STIX ID: report--d08aa123-158a-593a-a15d-6c9317cd0b7b
Feed Name: The Register (Security)
Citizen Lab identified a targeted phishing and supply-chain campaign aimed at Uyghur diaspora members and World Uyghur Congress affiliates: attackers sent spoofed emails with Google Drive links to a password-protected RAR that contained a trojanized Windows build of the UyghurEditPP text editor. The altered application included a backdoor enabling information collection, file exfiltration, and downloading/installing additional malware plugins; the attack relied on high-quality social engineering and likely leveraged trust relationships within the community. Researchers did not attribute a specific actor but noted parallels to prior China-linked tactics; the campaign showed no zero-day exploitation and had limited technical sophistication, and affected recipients were alerted by Google and not widely deceived.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
