Summary
This advisory includes two case studies detailing techniques used by malicious cyber actors using spyware known as BADBAZAAR and MOONSHINE to target data on mobile devices including smartphones that could be of interest to the Chinese state. It also signposts to guidance to help individuals protect themselves, their Alongside this advisory, the NCSC has published full technical detail with separate The authoring agencies and industry partners have observed BADBAZAAR and MOONSHINE specifically targeting individuals connected to topics considered by the Chinese state to be a threat to their domestic authority, ambitions and global reputation. Those most at risk include, but are not limited to, anyone connected to: > Uyghur Muslims and other ethnic minorities in or from China’s Xinjiang > democracy advocacy (including Hong Kong) > the Falun Gong spiritual movement This includes non-governmental organisations (NGOs), journalists, businesses and individuals who advocate for, identify with, or otherwise represent these groups. The indiscriminate way this spyware is spread online also means there is a risk that infections could spread beyond intended victims. This advisory aims to help those at risk respond effectively to the specific threat from BADBAZAAR and MOONSHINE spyware.