BADBAZAAR
BadBazaar is a mobile surveillanceware family with Android and iOS variants. Public reporting in the provided content ties it to China-aligned activity, including attribution to APT15 and reporting linking active Android campaigns to GREF; Volexity tracks related activity under the actor name EvilBamboo. It has been used primarily against Uyghur, Tibetan, and Taiwanese individuals and related civil society organizations, with broader references to targets connected to democracy activism, Falun Gong, and other communities viewed as sensitive by the Chinese state.
BadBazaar is commonly delivered through trojanized or legitimate-looking mobile applications, including fake or modified messaging apps and community-themed apps. Reported lures and app themes include Signal Plus Messenger, FlyGram, WhatsApp- and Telegram-themed apps, prayer and religious apps, dictionaries, radio apps, utilities, PDF readers, and the iOS app TibetOne. Distribution channels mentioned in the content include dedicated websites such as signalplus[.]org and flygram[.]org, Telegram channels and groups such as tibetanphone, Reddit/forum promotion, Google Play, Samsung Galaxy Store, and in one case Apple’s App Store.
On Android, reported capabilities include collection of device and operator information, contacts, call logs, SMS messages including real-time forwarding, installed apps, files, photos, Wi-Fi information, Google account emails, location data, and in some variants retrieval of Telegram-related files. Volexity reported BADBAZAAR second-stage functionality for file listing and retrieval, photo capture, contact theft, call-log theft, SMS theft, device information collection, and location collection. ESET reported that Signal Plus Messenger abused Signal’s linked-device feature to silently link a victim’s Signal account to an attacker-controlled device and steal the Signal PIN, enabling surveillance of Signal communications. FlyGram also included a malicious Cloud Sync feature that uploaded Telegram backups and metadata to attacker-controlled infrastructure.
On iOS, the content states the BadBazaar variant had more limited functionality than Android but still exfiltrated device name, device type, local IP, OS version, UDID, and location. The iOS TibetOne sample sent data to tryhrwserf[.]com:4432, including /api/iosvalues and /api/ioslogin, used SSL pinning with embedded certificate WIN-I6VBN8MR92A.cer (SHA1 55191348eb763dc853a719c0f3defdbe354127db), and abused location permissions by presenting weather information via the OpenWeatherMap API. Reporting also noted iOS-related endpoints such as api/IosUploadFile on related infrastructure, suggesting possible file-exfiltration development.
Infrastructure and IoCs directly mentioned in the content include signalplus[.]org:4332, flygram[.]org:4432, tryhrwserf[.]com:4432, tibetone[.]org, xle.clublogs[.]com, clublogs[.]com, actuallys[.]com, rewrwer[.]com, www.voiceoftibet[.]net, myloughborough[.]com, pmstwocqn[.]com, collinformations[.]com, and androidupdated[.]net. Reported infrastructure characteristics include Windows-hosted ASP.NET C2 servers, common API ports 4432 or 4332, RDP on 56931, and reused certificate/machine names such as WIN-50QO3EIRQVP, WMSvc-WIN-50QO3EIRQVP, WIN-EU0VLBL7TUJ, and WIN-70E59JVOB9G. The content also notes WHOIS artifacts and registration overlaps involving keyboard-walk values and emails such as tplutalova@list.ru, ivan_s81@mail.ru, and ocean.nio@rediffmail.com.
The content further notes that BadBazaar has been described in some reporting as a banking trojan, and more recent telemetry cited it among spyware families driving increased Android spyware activity. Overall, the high-confidence characterization in the provided material is that BadBazaar is a long-running mobile spyware/surveillanceware family used in targeted espionage and monitoring campaigns against politically sensitive communities.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malicious code found in these apps is attributed to the BadBazaar malware family, which has been used in the past by a China-aligned APT group called GREF.
BADBAZAAR is a mobile malware with iOS and Android variants that have targeted Uyghurs, Tibetans and Taiwanese individuals.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 techniqueAPT15 developed its own malware, allowing it to persist within victim networks (T1587.001).
Initial Access
3 techniquesThe PRC has been publicly linked to cyber espionage operations against the Uyghur minority group, including members living in Canada, using spear phishing emails and spyware.
The app was circulated in targeted Telegram channels and Reddit forums where members of the Tibetan community gather.
BADBAZAAR is spread via social media platforms and official app stores.
Execution
1 techniqueYouTube videos (promoting the use of the malicious applications) were created by the malicious cyber actors. These videos included tutorials on how to use the applications developed.
Stealth
1 techniqueSome infected apps mimic popular platforms like WhatsApp or Skype, while others are standalone applications designed to appear trustworthy, especially to users from the affected regions.
Collection
1 techniqueThese two spywares hid inside legitimate-looking Android apps, acting essentially as “Trojan” malware, with surveillance capabilities such as the ability to access the phone’s cameras, microphone, chats, photos, and location data...
IOCs tracked for this family
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as targeting mobile users via fake apps; details not provided in the excerpt.
Android spyware family associated with surveillance, extortion, and identity theft activity.
Malware referenced via NCSC UK advisory in connection with MOONSHINE and UPSEC; no additional functional details provided in this content.
Spyware embedded in mobile apps that covertly accesses microphones, cameras, messages, photos, and location data, enabling real-time surveillance of targets. It was specifically deployed via the Tibet One iOS app.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.