Tired of ads? Enjoy an ad-free experience by signing up.
Steven Millward · · 3 min read

Now China Seems to be Targeting Human Rights Activists with Android Spyware

political Android spyware from China

Malware and spyware attacks on Chinese dissident groups have usually been focused on PC, Mac, or email accounts. But now specially-made infectious Android apps are a threat as well. Security researchers at Kaspersky say they’ve found a targeted malware attack on Android phones that seems to come from China. It seeks to steal information like contacts, call logs, and SMS of people who work in the field of human rights, especially related to China’s Tibet and Xinjiang provinces.

It started earlier this week when, the Kaspersky team explains, “the e-mail account of a high-profile Tibetan activist was hacked and used to send spear phishing e-mails to their contact list.” Attached to those mails is malware masquerading as a useful app related to an event with the file-name “WUC’s Conference.apk”. If a user downloads and installs the file (as needs to be done with any Android app), it “secretly reports the infection to a command-and-control server” and begins stealing infomation on the human rights worker, such as:

  • Contacts (stored both on the phone and the SIM card)
  • Call logs
  • SMS messages
  • Geo-location
  • Phone data (phone number, OS version, phone model, SDK version)
Android spyware from China targets human rights

It starts with spear-phishing…

Android spyware from China targets human rights

…And might end up with you installing spyware.

Although the app looks basic, the researchers find that it’s pretty efficient at its sole task of harvesting information on the phone’s users and his/her network of contacts.

Calling home

Aside from this Android spyware attacking groups of which Chinese authorities have long been wary, what’s the proof of the nation’s involvement? Though the malware’s command-and-control server points to Los Angeles in the US, the server is newly registered to a company named Shanghai Meicheng that’s actually registered in Beijing. Plus, within the app itself the security team found lines of Chinese text in the logs. Kaspersky warns on its blog:

It is perhaps the first in a new wave of targeted attacks aimed at Android users. So far, the attackers relied entirely on social engineering to infect the targets. History has shown us that, in time, these attacks will use zero-day vulnerabilities, exploits or a combination of techniques.

Politically-motivated hack attacks caused yet another kerfuffle for Google in China back in the summer of 2011. On that occasion, a vulnerability in Adobe Flash tweaked the Gmail settings of infected users – it seemed aimed at foreign journalists in China – to forward email to a mysterious Big Brother.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Steven Millward

Interested in ecommerce, social media, gadgets, transportation, and cars. If you have any tips or feedback, contact via Twitter: @sirsteven