logo

China-Linked Hackers Continue Harassing Ethnic Groups With Spyware

ID: 0eef5857-8e9f-5c93-9015-12fc2e589b62

STIX ID: report--0eef5857-8e9f-5c93-9015-12fc2e589b62

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-04-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

UK NCSC and several international agencies warn of active China-linked mobile spyware campaigns using BadBazaar and Moonshine to target Uyghur, Tibetan, Taiwanese, Hong Kong pro-democracy activists and related communities. Malicious apps (e.g., an "Audio Quran.apt" package and a bogus "TibetOne" app), Telegram channels, Reddit and a dedicated website are being used to distribute the spyware; capabilities include location tracking, live audio/photo capture and file exfiltration. The advisory emphasizes risk of collateral infections and recommends downloading only from official app stores, keeping devices updated, avoiding jailbreaking, reviewing app permissions, and removing unneeded apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.