logo

Open source text editor poisoned with malware to target Uyghur users

ID: d08aa123-158a-593a-a15d-6c9317cd0b7b

STIX ID: report--d08aa123-158a-593a-a15d-6c9317cd0b7b

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-04-29

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Citizen Lab identified a targeted phishing and supply-chain campaign aimed at Uyghur diaspora members and World Uyghur Congress affiliates: attackers sent spoofed emails with Google Drive links to a password-protected RAR that contained a trojanized Windows build of the UyghurEditPP text editor. The altered application included a backdoor enabling information collection, file exfiltration, and downloading/installing additional malware plugins; the attack relied on high-quality social engineering and likely leveraged trust relationships within the community. Researchers did not attribute a specific actor but noted parallels to prior China-linked tactics; the campaign showed no zero-day exploitation and had limited technical sophistication, and affected recipients were alerted by Google and not widely deceived.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.