Researchers reported an intensifying cyber-espionage campaign targeting Uyghur macOS users, with attackers focusing on a politically sensitive community through tailored malware and surveillance activity. The operation was described as part of broader efforts to compromise devices used by Uyghur individuals, likely to collect intelligence, monitor communications, and maintain persistent access to victims’ systems.
The activity highlights that macOS users in high-risk communities are being singled out with targeted attacks rather than broad commodity malware. The reporting indicates the campaign was notable for its focus on Uyghur users and for demonstrating that threat actors continue to adapt their tooling and delivery methods to Apple platforms in support of long-term espionage objectives.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky's Securelist published research describing an intensification of cyber attacks targeting Uyghur Mac OS X users. The reference indicates a targeted campaign affecting this community, but no earlier discrete events are provided in the supplied content.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.