logo

Trojanized Text Editor Software Used in Targeted Uyghur Spy Campaign

ID: daf61fb2-90f4-5512-bb9f-021324a1d75c

STIX ID: report--daf61fb2-90f4-5512-bb9f-021324a1d75c

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2025-04-28

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

Citizen Lab discovered a targeted cyber-espionage campaign (March 2025) that weaponized the open-source UyghurEditPP text editor to deploy a modular backdoor against World Uyghur Congress members and Uyghur diaspora; the malware exfiltrates system data, performs file operations and command execution, communicates with C2 domains (e.g., tengri.ooguy.com, anar.gleeze.com) using cloud-hosted infrastructure and fake Microsoft TLS certificates, and is distributed via spearphishing and fake download sites (gheyret.com/.net), representing a sophisticated, culturally tailored surveillance operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.