← Back to advisories & guidance
April 9, 2025
NSA
Advisory
Co-sealed by: ASD/ACSC, CCCS, FBI, NCSC-NZ, NCSC-UK, NSA
Summary
BADBAZAAR and MOONSHINE: Technical With support from the UK Cyber League, this advisory has been jointly produced by the National Cyber Security Centre (NCSC UK) and international partners: > The Australian Cyber Security Centre, part of the Australian Signals > The Canadian Centre for Cyber Security, part of the Communications > The German Federal Intelligence Service > The German Federal Office for the Protection of the Constitution > The New Zealand National Cyber Security Centre, part of the Government Communications Security Bureau > The United States Federal Bureau of Investigation > The United States National Security Agency This advisory provides new and collated threat intelligence on two variants of spyware known as BADBAZAAR and MOONSHINE, and includes advice for app store operators, developers and social media companies to help keep their users safe. This advisory is being published in parallel with an advisory for victims of these This document uses the NCSC glossary definition of spyware: "A type of malware that installs on a device without the user's consent, collecting data and then MOONSHINE is an Android spyware reported in 2019 by Citizen Lab as targeting Tibetan groups. MOONSHINE masquerades as a legitimate app to lure victims into installing it.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.