By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: NCSC issues warning over Chinese Moonshine and BadBazaar spyware | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > NCSC issues warning over Chinese Moonshine and BadBazaar spyware | Computer Weekly
News

NCSC issues warning over Chinese Moonshine and BadBazaar spyware | Computer Weekly

News Room
Last updated: 2025/04/08 at 11:17 PM
News Room Published 8 April 2025
Share
SHARE

The UK’s National Cyber Security Centre (NCSC), the US’s National Security Agency (NSA) and the FBI, alongside Five Eyes partner agencies from Australia, Canada and New Zealand, and the German cyber authorities, have issued a series of advisories warning individuals at risk of hostile state surveillance to be alert to two spyware variants, dubbed Moonshine and BadBazaar.

So far, the malicious applications have been detected on the mobile devices of individuals considered to be of interest to the Chinese intelligence services. For now, their known victim profile appears to be limited to people associated with the Taiwanese, Tibetan and Uyghur Muslim communities, and other groups such as the Falun Gong movement.

However, given the scope of Beijing’s cyber espionage operations, they could easily be used against targets located in the West, conceivably including members of the Hong Kong diaspora and pro-democracy activists in the UK.

Moonshine and BadBazaar both employ a technique known as trojanising, whereby they hide their malicious functionality inside apparently legitimate applications, to access device functions such as microphones and cameras, location data, messages and photos.

“With our international and industry partners, we are committed to helping equip individuals at risk of online surveillance with the information they need to counter spyware threats,” said NCSC operations director Paul Chichester.

The NCSC urges people at higher risk to exercise heightened vigilance and follow our practical advice to help keep their devices and data safe
Paul Chichester, NCSC

“We are seeing a rise in digital threats designed to silence, monitor and intimidate communities across borders, and the use of these two forms of spyware is clearly unacceptable.

“The NCSC urges people at higher risk to exercise heightened vigilance and follow our practical advice outlined in the advisory to help keep their devices and data safe,” added Chichester.

Skype and WhatsApp both targeted

Among the trojanised apps discovered by the Five Eyes agencies are compromised instances of Microsoft’s soon-to-be-discontinued Skype and Meta’s WhatsApp messaging services.

However, both Moonshine and BadBazaar have also been observed hiding within apps that the threat actor behind the spying campaign appears to have designed to lure in victims.

Among them is an application called TibetOne, an iOS app designed to support language learning that has the ability to access device information and location data. The app was uploaded to the App Store as long ago as December 2021, but is no longer available.

A second app identified, Audio Quran.apk, was used specifically to target members of the Uyghur Muslim community located in China’s remote western Xinjiang region with Moonshine. The Turkic Uyghurs have been subject to repression by the Chinese authorities, which has been described as genocide by the Americans. Like TibetOne, Audio Quran collected a wealth of information from its victims.

New advice

Besides the two new advisories – one containing guidance for potential victims, the other a technical breakdown of each spyware, including advice for app store operators, developers and social media companies – the NCSC has also shared four key steps that all individuals, regardless of their risk profile, should be taking to safeguard their devices.

  1. Stay mainstream: Refrain from trying to jailbreak or root devices and only download applications from trusted app stores.
  2. Stay organised: Audit your installed apps, and their permissions, on a regular basis.
  3. Stay in touch: Report suspicious messages or files.
  4. Stay safe: Be cautious on social media, and check and review shared files or links for malicious activity.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article China carmakers post FY23 profit drops, partners hit by competition · TechNode
Next Article Trump’s DOJ will no longer prosecute cryptocurrency fraud
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Hand-Luggage Hacks For Early LGW Flights
Gadget
AI better at predicting scientific results than humans – study
Software
New technique supported by AI allows to reduce the restoration time of damaged art
Mobile
How Black Friday is being reshaped by Chinese e-commerce platforms before Trump returns · TechNode
Computing

You Might also Like

News

Apple Says iPhone Games Can Offer Redemption Codes Later This Year

6 Min Read
News

FIFA Club World Cup Soccer: Stream Al Ahly vs. Inter Miami Live From Anywhere

10 Min Read
News

ChatGPT Gets ‘Absolutely Wrecked’ in Chess Match With 1978 Atari

5 Min Read
News

Act fast to score the Samsung Galaxy Watch 7 at its best-ever price at Amazon

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?