BadBazaar is a mobile spyware family with Android and iOS variants used in China-aligned cyberespionage campaigns targeting Uyghur, Tibetan, and Taiwanese individuals, diaspora communities, and associated civil society organizations. It has been attributed to APT15/GREF, while related campaigns have also been tracked as EvilBamboo. Android samples date to at least late 2018.
BadBazaar conceals surveillance functions within otherwise functional mobile applications, including messaging clients, religious and cultural applications, dictionaries, media players, and utilities. Operators distribute these applications through social media, messaging groups, community forums, download sites, and official app stores. Distribution uses community-specific languages and interests, impersonation of trusted applications, and purported cracked software. The TibetOne iOS application was available through Apple's App Store before its removal.
Android variants can download and load additional surveillance payloads and support theft of SMS messages, including real-time forwarding, call logs, contacts, files, device information, and location data. They can also enumerate installed applications and capture photographs. The analyzed iOS variant has more limited functionality, exfiltrating device identifiers, operating-system information, and location data over TLS connections with certificate pinning. Public naming conventions differ: some messaging-app variants classified as BadBazaar are separately tracked as BadSignal and can silently link an attacker-controlled device to a victim's Signal account, allowing access to subsequent messages. BadBazaar's collection capabilities enable covert monitoring of politically sensitive communities both within China and abroad.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Case study two: BADBAZAAR. BADBAZAAR is a mobile malware with iOS and Android variants that have targeted Uyghurs, Tibetans and Taiwanese individuals. This spyware is spread via social media platforms and official app stores.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious scripts are hidden in otherwise legitimate apps and uploaded to app stores
The actors try to make their spyware appear more legitimate by uploading it to official app stores such as the Google Play Store and the Apple App Store or by adding malicious code to previously benign apps.
MOONSHINE masquerades as a legitimate app to lure victims into installing it. It has been shared via Telegram channels and links sent via WhatsApp.
The PRC has been publicly linked to cyber espionage operations against the Uyghur minority group, including members living in Canada, using spear phishing emails and spyware.
Examples include ‘Tibet One’ and Audio Quran apps that have supported targets’ native languages and were promoted in online forums frequented by intended users, as well as some apps imitating the likes of legitimate brands such as Whatsapp and Skype.
174 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile surveillance family reported on Android and iOS and attributed by Lookout to APT15 with high confidence. Shares infrastructure with DoubleAgent, with samples dating to late 2018 and distribution through Uyghur-language channels continuing in 2022.
Referenced only as an espionage-related incident on the same hosting provider; no CRPX0 operational relationship is stated.
Malware referenced as targeting mobile users via fake apps; details not provided in the excerpt.
Android spyware family associated with surveillance, extortion, and identity theft activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.