A cyber-espionage campaign targeted a small number of Uyghur individuals and Uyghur-supporting organizations in Xinjiang, Pakistan, and other parts of China using malicious documents and spoofed charity and human-rights websites. Researchers said the operation used United Nations-themed lures and fake domains including officemodel[.]org, unohcr[.]org, and tcahf[.]org to deliver Windows implants identified as WebAssistant and TcahfUpdate.
The malware collected host information, including system identifiers, running processes, and installed software, while also establishing persistence and retrieving additional payloads from attacker-controlled infrastructure. Investigators observed anti-VM behavior and possible checks for security tools, and attributed the activity with low-to-medium confidence to a Chinese-speaking threat actor based on the victimology and code clues; newly registered domains tied to the same infrastructure indicated the campaign remained active into 2021.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Check Point Research and Kaspersky GReAT reported that the espionage campaign targeting Uyghur individuals and supporting organizations remained active into 2021. They linked newly registered domains to the same attacker infrastructure.
The same fake tcahf[.]org website later served a different Windows implant family, TcahfUpdate, indicating an evolution in the campaign's tooling. Researchers observed this second implant family in October 2020.
The fake Turkic Culture and Heritage Foundation website tcahf[.]org served a Windows implant family called WebAssistant to targets posing as a security scanner for grant applicants. Researchers observed this malware family on the site in May 2020.
The domain officemodel[.]org, used to deliver malicious templates from a UN-themed lure document, resolved to the same IP address as unohcr[.]org, a fake UN human-rights site. The shared infrastructure was observed between April and December 2020.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.