EvilBamboo, formerly tracked as Evil Eye, is a long-running espionage threat actor assessed to operate in the interest of the Chinese state. The group has conducted sustained surveillance campaigns for more than five years focused on Tibetan, Uyghur, and Taiwanese individuals and organizations, including communities and causes viewed by Beijing as politically sensitive. Its operations are notable for mobile-device targeting, especially Android spyware delivery, with evidence of iOS targeting as well. EvilBamboo is associated with the development and deployment of multiple custom Android spyware families, including BADBAZAAR, BADSIGNAL, and BADSOLAR. These implants have been embedded into trojanized versions of legitimate applications and distributed through fake websites, social media personas, Telegram channels and groups, and forum posts. The actor has impersonated widely used messaging, communications, mapping, and utility applications to induce installation by targets. The group’s tooling supports extensive post-compromise surveillance and data theft. Reported capabilities include collection of device information, contacts, call logs, location data, files, installed application lists, and photos, as well as SMS interception and real-time forwarding. BADSIGNAL has additionally been used to abuse Signal account-linking features, steal Signal PINs, and force proxy usage, enabling monitoring of new Signal messages. BADSOLAR has used staged payload delivery, including retrieval of a second-stage component derived from AndroRAT. EvilBamboo has also used a custom JavaScript profiling framework known as JMASK on attacker-controlled sites to fingerprint visitors and identify likely victims, including potential gating for iOS-focused exploitation. The actor demonstrates persistent operational investment, tailored victimology, and multi-platform tradecraft oriented toward covert intelligence collection rather than disruption or monetization. Known aliases include Evil Eye.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.