- Malicious applications are disguised to collect data for China
- Uighour, Tibetan and Taiwanese communities are targeted
- Applications resemble religious and cultural applications
The Uks National Cyber Security Center, alongside compatriots in Australia, Canada, Germany, New Zealand and the United States, is warning that the applications loaded with spy software are used to target Uighour, Tibetan and Taiwanese communities.
The spy software, named Badbazaar and Monshine, is probably used to collect “use of China” information on people who could be a threat to China’s safety.
Many applications loaded with spy software are designed to imitate religious or cultural applications.
Gathering location, audio and photo data
The applications in question include “Audio Koran”, a religious application used to target Uighur and “Tibetone” communities which appears at first glance as an application used to share images, videos, music and articles celebrating Tibetan culture.
There have been attempts to share applications through legitimate channels such as Google Play Store, but these attempts have largely failed thanks to the security controls in the Play Store.
Consequently, applications have rather been shared on the forums frequented by target communities and counted on users who install applications via .apk files.
According to the NCSC report [PDF]Applications are not only used to target individuals, but are also used to monitor civil society groups to follow their activities.
Badbazaar and Monshine spy software could access data from real -time location and GPS data, live audio and video capture, files stored on the device, SMS and call newspapers and device information, as well as read audio via the device.
The joint declaration indicates: “Although Badbazaar and Monshine have been observed targeting the Uighur, Tibetan and Taiwanese individuals, there are other malicious software that targets other minority groups in China. Citizens of co-hole nations, in China and abroad, who are perceived as causes of defense that threaten the stability of the regime. ”
“The capacity to capture data on the location, the audio and the photo certainly offers the possibility of informing future surveillance and harassment operations by providing real -time information on the target activity.”




