Earth Empusa is a China-linked cyber-espionage threat actor known for targeting Uyghur, Tibetan, Turkish, and Taiwanese communities, as well as activists, journalists, and dissidents, particularly Uyghurs from Xinjiang living abroad. The group is also tracked as Evil Eye, and some reporting has historically associated it with POISON CARP, although later assessments have treated Earth Empusa as a distinct cluster with overlapping tradecraft. The actor is notable for mobile-focused espionage operations against both Android and iOS devices. On Android, Earth Empusa has deployed spyware including ActionSpy and PluginPhantom through phishing pages, fake app-store sites, and trojanized Uyghur-themed applications. ActionSpy masqueraded as a legitimate Uyghur video application while embedding the real app to preserve expected functionality, a technique that improved deception and persistence on victim devices. The malware supported extensive surveillance, including device profiling, location tracking, collection of contacts, call logs, SMS, browser data, installed applications, files, screenshots, audio, camera captures, and theft of chat content from messaging platforms such as WeChat, QQ, WhatsApp, and Viber. It also abused Android Accessibility services to monitor and extract communications. Earth Empusa has also conducted watering-hole operations by compromising legitimate websites and creating look-alike sites frequented by intended victims. These operations used frameworks such as ScanBox and BeEF for reconnaissance and victim profiling, and selectively delivered iOS exploitation only to devices matching desired operating system, browser, language, and geographic characteristics. The group has been linked to iOS malware referred to as INSOMNIA and to exploit-chain activity updated to target specific iOS versions in 2020. Its use of selective delivery, social engineering personas, and staged infrastructure indicates a well-resourced and persistent espionage capability focused on covert surveillance and account compromise. Observed targeting expanded from Tibet and Turkey to Taiwan in 2020, and reporting also identifies victims in Kazakhstan, the United States, Syria, Australia, and Canada. The actor has used phishing, watering holes, fake personas, compromised websites, and trojanized mobile applications to gain access and collect intelligence. Its dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a distinct intrusion set previously believed associated with POISON CARP, but not connected here to Earth Minotaur.
China-linked cyber-espionage activity targeting Uyghur activists, journalists, and dissidents abroad. Uses social engineering on Facebook to drive targets to malicious links, watering-hole compromises and look-alike news sites, selective targeting checks for iOS exploitation, and trojanized Uyghur-themed Android apps distributed via fake third-party app stores. Also leverages vendor-developed Android tooling.
Conducting mobile espionage campaigns against Uyghur-, Tibetan-, and related targets using phishing pages and watering hole attacks to compromise Android and iOS devices, including delivery of the ActionSpy Android spyware and iOS exploit chains.
Conducting mobile espionage campaigns against Uyghur-, Tibetan-, and related targets using phishing pages, watering hole attacks, Android spyware, and iOS exploit chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.