BadBazaar is a mobile surveillanceware family targeting Android and iOS devices. It is associated with China-aligned espionage activity and has been linked in public reporting to APT15 and to activity clusters tracked as GREF and EvilBamboo. The malware has primarily targeted Uyghur, Tibetan, and Taiwanese individuals and related civil society communities, including people connected to democracy advocacy and other topics viewed as politically sensitive by the Chinese state.
BadBazaar is typically embedded into trojanized mobile applications that otherwise appear legitimate, including messaging, religious, language, media, utility, and community-focused apps. Distribution has occurred through social media, messaging platforms, dedicated promotion channels, third-party downloads, and in some cases official app stores. Known campaigns used culturally tailored lures and impersonation of trusted brands or community services to increase installation rates.
On infected devices, BadBazaar supports covert surveillance and data theft. Reported capabilities across Android and iOS variants include collection of device and operator information, contacts, call logs, messages, photos, files, installed-application data, account information, and location data, including real-time tracking. Android variants have also been reported capturing or forwarding SMS data in real time, retrieving files, taking photos, and abusing messaging-app functionality for surveillance. One documented Android campaign used a trojanized Signal client to silently link a victim account to an attacker-controlled device, enabling monitoring of Signal communications. Related variants grouped with or adjacent to BadBazaar, such as BadSignal and BadSolar, share overlapping surveillance functions and infrastructure patterns.
The iOS variant has been observed with a narrower feature set than Android but still exfiltrates device and location information and shows signs of ongoing development. Public reporting has also noted infrastructure overlap and shared operational characteristics between Android and iOS deployments, including common backend patterns and promotion ecosystems.
BadBazaar is best characterized as spyware used for targeted mobile surveillance and intelligence collection rather than financially motivated crime. Its victimology, lure themes, and operational use strongly align with long-running monitoring of minority and dissident communities of interest to the Chinese state.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Case study two: BADBAZAAR. BADBAZAAR is a mobile malware with iOS and Android variants that have targeted Uyghurs, Tibetans and Taiwanese individuals. This spyware is spread via social media platforms and official app stores.
The malicious code found in these apps is attributed to the BadBazaar malware family, which has been used in the past by a China-aligned APT group called GREF.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious scripts are hidden in otherwise legitimate apps and uploaded to app stores
The actors try to make their spyware appear more legitimate by uploading it to official app stores such as the Google Play Store and the Apple App Store or by adding malicious code to previously benign apps.
MOONSHINE masquerades as a legitimate app to lure victims into installing it. It has been shared via Telegram channels and links sent via WhatsApp.
The PRC has been publicly linked to cyber espionage operations against the Uyghur minority group, including members living in Canada, using spear phishing emails and spyware.
174 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced as targeting mobile users via fake apps; details not provided in the excerpt.
Android spyware family associated with surveillance, extortion, and identity theft activity.
Spyware discussed as an example of modern spying tools that can pose as everyday apps and turn phones into surveillance devices.
Malware referenced via NCSC UK advisory in connection with MOONSHINE and UPSEC; no additional functional details provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.