NCSC Issues Alert on MOONSHINE and BADBAZAAR Malware

International cybersecurity agencies have issued joint advisories warning about sophisticated spyware targeting vulnerable ethnic and political groups.

The UK’s National Cyber Security Centre (NCSC), along with partner agencies from five countries, revealed details today about how malicious actors are deploying two forms of spyware against individuals in Uyghur, Tibetan, and Taiwanese communities worldwide

The malicious software variants – dubbed MOONSHINE and BADBAZAAR – hide within otherwise legitimate applications through a technique known as “trojanising,” enabling covert surveillance of targeted individuals.

Once installed, these apps can access device microphones, cameras, messages, photos, and location data without users’ knowledge, allowing real-time tracking and monitoring.

“We are seeing a rise in digital threats designed to silence, monitor, and intimidate communities across borders, and the use of these two forms of spyware is unacceptable,” said NCSC Director of Operations Paul Chichester in today’s announcement.

The advisory specifically warns that the spyware targets individuals internationally who are connected to topics the Chinese state considers threats to its stability.

Most at risk are people associated with Taiwanese independence movements, Tibetan rights organizations, Uyghur Muslims and other ethnic minorities from China’s Xinjiang region, democracy advocates, including those from Hong Kong, and members of the Falun Gong spiritual movement

Sophisticated Targeting Methods

Investigators found that some infected apps mimic popular platforms like WhatsApp and Skype, while others are standalone applications specifically designed to appeal to targeted communities.

For example, “Tibet One,” an iOS app written in Tibetan that was briefly available on the Apple App Store in December 2021, was designed to deploy BADBAZAAR spyware.

The malicious actors promoted this app in Telegram channels and Reddit forums frequented by the Tibetan community.

Similarly, the “Audio Quran” app used Uyghur language in its file name to target Muslims with MOONSHINE spyware.

The data collected through these applications is “almost certainly of value” to the Chinese government and could facilitate surveillance and harassment operations by providing real-time information on targets’ activities.

Protection Recommendations

The NCSC and partner agencies have outlined four key steps for individuals at higher risk to protect their devices:

  • Stay mainstream: Don’t jailbreak or root devices and only use trusted app stores
  • Stay organized: Review installed apps and permissions regularly
  • Stay in touch: Report suspicious messages and files to online services
  • Stay alert: Be vigilant on social media and carefully check shared files and links

A second advisory contains a technical analysis of the spyware and guidance for app store operators, developers, and social media companies to help protect users.

The advisories have been jointly published by cybersecurity agencies from the UK, Australia, Canada, Germany, New Zealand, and the United States, including the FBI and NSA, reflecting international concern about these surveillance operations.

“With our international and industry partners, we are committed to helping equip individuals at risk of online surveillance with the information they need to counter spyware threats,” Chichester added.

Experts say these spyware operations demonstrate evolving strategies in cyber surveillance, combining technical exploitation with culturally tailored social engineering to target specific communities.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories