Exiled Uyghur leaders targeted in sophisticated spear phishing campaign

Exiled Uyghur leaders targeted in sophisticated spear phishing campaign

A coordinated spear phishing campaign has targeted senior members of the exiled Uyghur community, delivering surveillance malware through an altered version of a trusted language tool, according to a new report from researchers at The Citizen Lab.

In March 2025, senior officials from the Munich-based World Uyghur Congress (WUC) received Google alerts about government-backed attempts to breach their accounts. A forensic investigation by The Citizen Lab revealed that the attacks deployed Windows malware disguised in a trojanized version of UyghurEditPP, an open-source text editor widely used within the Uyghur diaspora.

While the malware itself was not technically advanced, its method of delivery demonstrated a deep understanding of the Uyghur exile community and exploited trusted relationships. The tool was initially developed by a known figure within the community.

The attack infrastructure included two clusters of malicious domains, one mimicking the UyghurEditPP developer and another using Uyghur-language terms in its URLs, both tied to IP addresses managed by Choopa LLC, a provider previously linked to cyber threat actors. The campaign is believed to have been in development since May 2024.

Once installed, the malware profiled infected systems and connected to a command-and-control server to receive further instructions, including uploading or downloading files and executing additional code. The attackers’ apparent goal was to gather intelligence on legitimate Uyghur community members.

The Citizen Lab believes that the attackers were likely aligned with Chinese state interests, given the targets and the tactics used.


Back to the list

Latest Posts

Cyber Security Week in Review: May 16, 2025

Cyber Security Week in Review: May 16, 2025

In brief: Microsoft, Fortinet, Ivanti, and Google patch zero-days, crypto exchange Coinbase reveals a data breach, and more.
16 May 2025
Russia-linked espionage operation targeting webmail servers via XSS flaws

Russia-linked espionage operation targeting webmail servers via XSS flaws

The campaign exploits XSS vulnerabilities in widely used webmail servers to steal sensitive data from high-value targets.
15 May 2025
Kosovo man extradited to US for running BlackDB.cc criminal marketplace

Kosovo man extradited to US for running BlackDB.cc criminal marketplace

If convicted on all counts, Masurica faces up to 55 years in federal prison.
14 May 2025