HomeSecurityEvilBamboo targets Tibetans and Taiwanese

EvilBamboo targets Tibetans and Taiwanese

Tibetan, Uyghur, and Taiwanese individuals and organizations are the targets of a persistent campaign orchestrated by a malicious actor codenamed EvilBamboo to collect sensitive information.

See also: HTX: Crypto Exchange Lost $8 Million in Ether Due to Hack

EvilBamboo targets Tibetans and Taiwanese

The EvilBamboo hacking group, previously identified as Evil Eye, has been linked to multiple waves of attacks since 2019, with the group exploiting watering hole attacks to deliver malware targeting Android and iOS. It is also known as Earth Empusa and POISON CARP.

See also: Researchers uncover a thriving underground economy for malware targeting IoT devices

Hackers targeting Apple's mobile operating system exploited a vulnerability in the WebKit browser engine that Apple had patched in early 2019 to deliver a spyware strain called Insomnia. Meta, in March 2021, said it had identified the malicious actor that was abusing its platforms to distribute malicious websites hosting the malware.

The group is also known for using Android malware, such as ActionSpy and PluginPhantom, to collect valuable data from compromised devices, under the guise of dictionary, keyboard, and prayer apps offered in third-party app stores.

The latest findings from Volexity attribute three new spying tools for Android to EvilBamboo, called BADBAZAAR, BADSIGNAL, and BADSOLAR, the first of which was documented by Lookout in November 2022.

A subsequent report last month by ESET analyzed two trojanized apps that impersonate Signal and Telegram on the Google Play Store to trick users into installing BADSIGNAL. While the Slovakian cybersecurity firm assigned the fake programs to the BADBAZAAR family, citing similar coding similarities, Volexity said they “also appear to differ in their development and functionality.”.

The attack chains used to distribute the malware families include the use of APK sharing forums, fake websites advertising Signal, Telegram, and WhatsApp, Telegram channels dedicated to sharing Android apps, and a set of fake profiles on Facebook, Instagram, Reddit, X (formerly Twitter), and YouTube.

One of the channels on Telegram is said to have contained a link to an iOS app called TibetOne, which is no longer available on the App Store.

Messages shared through Telegram groups have also been used to distribute applications infected with the BADSOLAR malware, as well as to trap links that, when visited, execute malicious JavaScript to identify and capture the system.

While BADBAZAAR is primarily used to target Uyghurs and other Muslim individuals, BADSOLAR appears to be primarily used with Tibetan-themed applications. However, both variants incorporate their malicious capabilities in the form of a second phase retrieved from a remote server.

BADSOLAR's second-stage malware is also a variant of an open-source Android remote access trojan called AndroRAT. In contrast, BADSIGNAL includes all the information-gathering functionality in its main package.

Information source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS