logo

China Hackers Used Trojanized UyghurEditPP App to Target Uyghur Activists

ID: 11d69cbd-b06c-5a7e-a065-b6685adb8317

STIX ID: report--11d69cbd-b06c-5a7e-a065-b6685adb8317

Feed Name: HackRead

Threat Score
78/100

Date Published: 2025-04-30

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Citizen Lab reported a targeted spear-phishing campaign (March 2025) that delivered a Trojanized UyghurEditPP application to World Uyghur Congress members and activists; the backdoor harvested system identifiers and communicated with two distinct command-and-control clusters (domains mimicking the tool and Dynu-registered subdomains) allowing file transfer and remote plugin execution. Infrastructure overlap (shared Microsoft certificate, Choopa-hosted IPs), high-quality social engineering, and ties to transnational repression support probable Chinese state involvement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.