logo

EvilBamboo Targets Mobile Devices in Multi-year Campaign

ID: 867e6da4-3be8-5314-b669-413979921a22

STIX ID: report--867e6da4-3be8-5314-b669-413979921a22

Feed Name: Volexity Blog

Threat Score
88/100

Date Published: 2023-09-22

Date Updated: 2026-05-01

...
...

Volexity documents long-running, active espionage campaigns by the China-aligned APT 'EvilBamboo' that deploys multiple custom mobile spyware families (BADBAZAAR, BADSIGNAL, BADSOLAR) and supporting infrastructure (fake websites, Telegram channels, profiling JS, C2 servers) to target Tibetan, Uyghur, and Taiwanese communities; the report details malware capabilities, distribution methods including backdoored apps and App Store delivery, evidence of iOS profiling/exploitation, and provides IOCs and YARA rules for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.