logo

Windows Backdoor Targets Members of Exiled Uyghur Community

ID: 3b272a18-aa25-56c5-b642-30eb5deedf0c

STIX ID: report--3b272a18-aa25-56c5-b642-30eb5deedf0c

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-04-29

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers at the University of Toronto’s Citizen Lab uncovered a spear-phishing campaign targeting World Uyghur Congress members that delivered a Trojanized Uyghur language text editor (UyghurEditPP) via Google Drive links; the Windows backdoor collects system information, can download/upload files and run plugins, and uses a suspicious Microsoft-impersonating certificate with C2 infrastructure observed on Choopa LLC IPs. Active since mid-2024 with infrastructure movement through April, the campaign is attributed to likely China-aligned actors and highlights risks to diaspora and marginalized communities, along with recommendations to obtain software only from official, verified sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.