Lookout disclosed multiyear Android surveillance campaigns tied to China-origin activity that targeted the Uyghur ethnic minority and, to a lesser extent, Tibetans, using spyware families including SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle. The operations dated back to at least 2013 and relied on trojanized versions of legitimate apps that continued to function normally while covertly stealing contacts, messages, call records, device details, and location-related data for exfiltration to attacker-controlled infrastructure. Lookout linked the mobile activity to a broader surveillance toolkit that also included HenBox, PluginPhantom, Spywaller, and DarthPusher, and assessed that victims may have been affected across at least 14 countries, including Turkey, Kuwait, and Syria.
Citizen Lab documented an earlier, highly targeted Android malware campaign against prominent Tibetans that used forged emails and trojanized Kakao Talk and TuneIn Radio APKs to compromise devices. The malware preserved normal app behavior but added hidden spying functions, including periodic beaconing to android.uyghur.dnsd.me, encrypted configuration retrieval, data uploads, and the ability to respond silently to SMS commands with cellular network and base-station identifiers. The findings from both organizations show a long-running pattern of mobile espionage delivered through phishing and fake third-party app stores rather than Google Play, with overlaps in Uyghur-themed infrastructure and lures pointing to sustained surveillance of dissident communities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Lookout observed a dramatic increase in surveillanceware samples after Chinese national security and counterterrorism measures, including the Strike Hard Campaign against Violent Terrorism, were enacted in 2014 and 2015. The increase marked an escalation in the broader mobile surveillance activity targeting Uyghurs.
On April 18, 2013, Citizen Lab updated its report to note that a trojanized TuneIn Radio APK had circulated alongside the Kakao Talk sample in the same January 16 spoofed email. The TuneIn malware used the same fake signing certificate and was described as functionally identical.
Citizen Lab analyzed and disclosed a highly targeted Android malware operation against prominent members of the Tibetan community involving a trojanized Kakao Talk APK delivered by forged email. The report documented the malware's surveillance capabilities, C2 infrastructure, and overlap with Uyghur-themed infrastructure.
Citizen Lab reported that Avast, Lookout, and Kaspersky mobile scanners did not detect the compromised Kakao Talk app during tests conducted on February 6, 2013 and March 27, 2013. The finding suggested manual review of Android permissions was necessary to identify the threat at the time.
On January 16, 2013, a forged email impersonating the same security expert was sent to a high-profile Tibetan political figure with a compromised Kakao Talk APK attached. The malware preserved normal chat functionality while adding spyware features and communicated with the C2 domain android.uyghur.dnsd.me.
Lookout reported that interconnected Android surveillance campaigns using SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle date back to at least 2013. The China-origin activity primarily targeted Uyghurs and, to a lesser extent, Tibetans through trojanized apps and other delivery methods.
On December 4, 2012, a Tibetan community information security expert sent a legitimate private email to a member of the Tibetan parliament-in-exile in Dharamsala, India, attaching genuine Kakao Talk and TuneIn APK files. Citizen Lab later assessed attackers likely accessed this message via a compromised email account and reused it in a targeting operation.
Lookout reported four Android surveillanceware families—SilkBean, DoubleAgent, CarbonSteal, and GoldenEagle—as part of broader China-origin mobile APT campaigns targeting Uyghurs and some Tibetans. The company also linked the mobile activity to GREF/APT15-related desktop activity and assessed that at least 14 countries may have been affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.lookout.com
Open sourcecitizenlab.ca
Open sourcelookout.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.