HomeSecurityHackers use WhatsApp to target Tibetan residents

Hackers use WhatsApp to target Tibetans

hacker

A new series of attacks using a malicious one-click link to trick Tibetans is believed to have been launched by a hackingknown as “Poison Carp.” Canadian cybersecurity firm The Citizen Labfirst reported to The Hacker News that the Poison Carp group is sending a malicious link to targeted individuals, pretending to be NGO workers, journalists, or other similar professions.

Hackers aim to infect a systemin order to take control of it, including the camera and microphone, so they can perform various activities, steal contacts, call and location data, and private conversations, as well as automatically download malicious plug-ins to target devices.

The malicious one-click links, spread via WhatsApp , exploit multiple vulnerabilities in Android browsers as well as spyware kits. They can also exploit a phishingto steal financial data. The suspicious sources from which the attacks originate are not entirely unknown and have been observed before, such as in the iOS reported by Google.

The report, written by a team of seven researchers and their collaborators at The Citizen Lab, states that the primary targets of these attacks, which took place between November 2018 and May 2019, include the Dalai Lama’s private office, the Central Tibetan Administration, and the Tibetan Parliament. While there is no concrete evidence, the researchers believe that the Poison Carp group may originate in China and is likely funded by the country’s own government.

Despite the fact that the threat is quite serious, it is important to note that researchers have not found any zero-day exploits, which means that the companies concerned such as Google, Apple and WhatsApp will have already released patches to fix the flaws that hackers can exploit to compromise the data of these individuals. It is therefore recommended, especially for members of the Tibetan community, to always keep their systems up to date.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS