CyberzSOC

Publication detail
← Back to advisories & guidance

BADBAZAAR and MOONSHINE: Spyware Targeting Uyghur, Taiwanese, and Tibetan Groups and Civil Society Actors ↗ source

April 9, 2025 NSA Alert
Co-sealed by: ASD/ACSC, CCCS, FBI, NCSC-NZ, NCSC-UK, NSA

Summary

This advisory includes two case studies detailing techniques used by malicious cyber actors using spyware known as BADBAZAAR and MOONSHINE to target data on mobile devices including smartphones that could be of interest to the Chinese state. It also signposts to guidance to help individuals protect themselves, their Alongside this advisory, the NCSC has published full technical detail with separate The authoring agencies and industry partners have observed BADBAZAAR and MOONSHINE specifically targeting individuals connected to topics considered by the Chinese state to be a threat to their domestic authority, ambitions and global reputation. Those most at risk include, but are not limited to, anyone connected to: > Uyghur Muslims and other ethnic minorities in or from China’s Xinjiang > democracy advocacy (including Hong Kong) > the Falun Gong spiritual movement This includes non-governmental organisations (NGOs), journalists, businesses and individuals who advocate for, identify with, or otherwise represent these groups. The indiscriminate way this spyware is spread online also means there is a risk that infections could spread beyond intended victims. This advisory aims to help those at risk respond effectively to the specific threat from BADBAZAAR and MOONSHINE spyware.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.