Earth Empusa is a China-aligned cyber-espionage threat actor known for targeting ethnic and political minority communities, activists, journalists, dissidents, and related civil society networks, with a particular focus on Uyghur and Tibetan targets and associated communities abroad. Reported target locations have included Turkey, Kazakhstan, the United States, Syria, Australia, Canada, Taiwan, and other regions connected to diaspora populations and regional political interests. The group is also tracked under the aliases Evil Eye and, in some reporting, Poison Carp, although some researchers assess Poison Carp as a separate but overlapping cluster. Earth Empusa is notable for mobile-focused intrusion activity spanning both Android and iOS, combined with social engineering, phishing, watering-hole compromises, and fake online personas. The actor has used fraudulent accounts impersonating journalists, students, human rights advocates, and community members to build trust and deliver malicious links. It has also operated look-alike websites and compromised legitimate sites frequented by intended victims, including news and community-interest pages, to selectively deliver malware or exploit code. On Android, Earth Empusa has been linked to spyware families including ActionSpy and PluginPhantom. These implants have been distributed through trojanized themed applications, including apps tailored to Uyghur or Tibetan users, and through fake third-party app-store infrastructure. ActionSpy in particular has been described as a surveillance-oriented implant capable of collecting device metadata, contacts, call logs, SMS, location data, browser data, installed application information, files, screenshots, audio, camera captures, and messaging content. It abuses Android Accessibility services to harvest conversations from messaging applications such as WeChat, QQ, WhatsApp, and Viber, reflecting a strong emphasis on monitoring communications within targeted communities. On iOS, Earth Empusa has conducted watering-hole operations using selective delivery logic to profile visitors and serve exploit chains only to intended victims based on factors such as operating system, browser, language, geography, and other environmental characteristics. The actor has been associated with iOS malware referred to as INSOMNIA and with exploit infrastructure designed to infect narrowly selected devices while reducing exposure and complicating attribution. Earth Empusa has also used web-based reconnaissance and post-compromise tooling, including frameworks such as ScanBox and BeEF, to profile victims and support follow-on exploitation. Its operations demonstrate sustained investment in operational security, victim selection, and malware development, although some campaigns have also shown infrastructure overlap and tooling relationships with other Chinese intrusion activity. Reporting has linked portions of its Android tooling ecosystem to commercial developers in China, further suggesting access to specialized development resources. Overall, Earth Empusa is best characterized as a persistent, well-resourced Chinese espionage actor specializing in surveillance of politically sensitive populations through mobile malware, watering-hole attacks, phishing, and social engineering, with a particular concentration on Uyghur and Tibetan targets and adjacent advocacy, media, and diaspora networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a distinct intrusion set previously believed associated with POISON CARP, but not connected here to Earth Minotaur.
China-linked cyber-espionage activity targeting Uyghur activists, journalists, and dissidents abroad. Uses social engineering on Facebook to drive targets to malicious links, watering-hole compromises and look-alike news sites, selective targeting checks for iOS exploitation, and trojanized Uyghur-themed Android apps distributed via fake third-party app stores. Also leverages vendor-developed Android tooling.
Conducting mobile espionage campaigns against Uyghur-, Tibetan-, and related targets using phishing pages and watering hole attacks to compromise Android and iOS devices, including delivery of the ActionSpy Android spyware and iOS exploit chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.