China-Linked Hackers Continue Harassing Ethnic Groups With Spyware
ID: 0eef5857-8e9f-5c93-9015-12fc2e589b62
STIX ID: report--0eef5857-8e9f-5c93-9015-12fc2e589b62
Feed Name: Dark Reading
Date Published: 2025-04-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
UK NCSC and several international agencies warn of active China-linked mobile spyware campaigns using BadBazaar and Moonshine to target Uyghur, Tibetan, Taiwanese, Hong Kong pro-democracy activists and related communities. Malicious apps (e.g., an "Audio Quran.apt" package and a bogus "TibetOne" app), Telegram channels, Reddit and a dedicated website are being used to distribute the spyware; capabilities include location tracking, live audio/photo capture and file exfiltration. The advisory emphasizes risk of collateral infections and recommends downloading only from official app stores, keeping devices updated, avoiding jailbreaking, reviewing app permissions, and removing unneeded apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
