logo

'Earth Minotaur' Exploits WeChat Bugs, Sends Spyware to Uyghurs

ID: 5a72a884-2d12-5045-acf8-4bb920265381

STIX ID: report--5a72a884-2d12-5045-acf8-4bb920265381

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-12-05

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro reports that an actor tracked as Earth Minotaur is using the Moonshine exploit kit to target vulnerabilities in instant-messaging apps (including WeChat) and Chromium-based browsers to deliver DarkNimbus — a comprehensive Android/Windows surveillance backdoor — to Tibetan and Uyghur users; the campaign uses social-engineered malicious links, updated exploit modules to hinder analysis, and enables wide-ranging data exfiltration (contacts, messages, calls, location, recordings, screenshots) and remote command execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.