Windows Backdoor Targets Members of Exiled Uyghur Community
ID: 3b272a18-aa25-56c5-b642-30eb5deedf0c
STIX ID: report--3b272a18-aa25-56c5-b642-30eb5deedf0c
Feed Name: Dark Reading
Date Published: 2025-04-29
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at the University of Toronto’s Citizen Lab uncovered a spear-phishing campaign targeting World Uyghur Congress members that delivered a Trojanized Uyghur language text editor (UyghurEditPP) via Google Drive links; the Windows backdoor collects system information, can download/upload files and run plugins, and uses a suspicious Microsoft-impersonating certificate with C2 infrastructure observed on Choopa LLC IPs. Active since mid-2024 with infrastructure movement through April, the campaign is attributed to likely China-aligned actors and highlights risks to diaspora and marginalized communities, along with recommendations to obtain software only from official, verified sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
