China Hackers Used Trojanized UyghurEditPP App to Target Uyghur Activists
ID: 11d69cbd-b06c-5a7e-a065-b6685adb8317
STIX ID: report--11d69cbd-b06c-5a7e-a065-b6685adb8317
Feed Name: HackRead
Citizen Lab reported a targeted spear-phishing campaign (March 2025) that delivered a Trojanized UyghurEditPP application to World Uyghur Congress members and activists; the backdoor harvested system identifiers and communicated with two distinct command-and-control clusters (domains mimicking the tool and Dynu-registered subdomains) allowing file transfer and remote plugin execution. Infrastructure overlap (shared Microsoft certificate, Choopa-hosted IPs), high-quality social engineering, and ties to transnational repression support probable Chinese state involvement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
