Trojanized Text Editor Software Used in Targeted Uyghur Spy Campaign
ID: daf61fb2-90f4-5512-bb9f-021324a1d75c
STIX ID: report--daf61fb2-90f4-5512-bb9f-021324a1d75c
Feed Name: The Cyber Express
Citizen Lab discovered a targeted cyber-espionage campaign (March 2025) that weaponized the open-source UyghurEditPP text editor to deploy a modular backdoor against World Uyghur Congress members and Uyghur diaspora; the malware exfiltrates system data, performs file operations and command execution, communicates with C2 domains (e.g., tengri.ooguy.com, anar.gleeze.com) using cloud-hosted infrastructure and fake Microsoft TLS certificates, and is distributed via spearphishing and fake download sites (gheyret.com/.net), representing a sophisticated, culturally tailored surveillance operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
