Researchers reported that the Scarlet Mimic threat group conducted a years-long mobile surveillance operation targeting the Uyghur community and associated activists, with activity traced from 2015 through at least mid-2022. The campaign used Android malware known as MobileOrder, delivered outside Google Play through social-engineering lures disguised as Uyghur-themed PDFs, images, and audio files, continuing a broader espionage pattern previously linked to Scarlet Mimic’s targeting of minority activists.
Once installed, the spyware enabled extensive device monitoring and control, including data theft, location tracking, call and SMS abuse, call recording, ambient audio capture, screenshot collection, remote shell access, and installation of additional APKs. Researchers said the malware evolved over time with updated string obfuscation, dead-drop resolvers hosted on Sina blogs, AES-encrypted command-and-control traffic, and a move from the AMAP SDK to Android LocationListener for real-time tracking, reinforcing the assessment that Scarlet Mimic maintained a sustained and adaptive surveillance campaign against Uyghurs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The newest MobileOrder variant discussed by Check Point was dated to mid-August 2022. Check Point linked these newer samples to Scarlet Mimic through code similarity, shared infrastructure, and victimology.
Check Point reported observing a new wave of the long-running mobile surveillance campaign in 2022. The activity continued to target Uyghurs and related supporters using updated MobileOrder spyware variants.
The campaign was first publicly linked to Scarlet Mimic in 2016. A Unit 42 report from that year covered a years-long espionage campaign targeting minority activists under the Scarlet Mimic name.
Check Point said the MobileOrder Android spyware campaign targeting the Uyghur community has been active since 2015, with more than 20 samples identified over time. The malware was spread via social-engineering lures disguised as Uyghur-themed PDFs, images, and audio files outside Google Play.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.