Spyware accessing phone audio and cameras for data ‘of use to China’, NCSC warns

9 April 2025, 00:04

Person in yellow coat using smartphone on a train
Male person using smartphone while traveling by train mobile phone in hands close up. Picture: PA

The apps inside legitimate software in a technique known as trojanising, cyber experts warn.

Uighur, Tibetan and Taiwanese communities across the world are being targeted by spyware apps combing data likely to be of value to China, UK cyber experts have warned.

Malicious software dubbed MOONSHINE and BADBAZAAR is accessing microphones, cameras, messages, photos and location data without users being aware, GCHQ’s National Cyber Security Centre (NCSC) said.

The apps hide inside legitimate software in a technique known as trojanising, and are being used specifically to target individuals internationally who are linked to issues considered by Beijing to pose a threat to its security, experts warn.

In new guidance, the NCSC, along with agencies in Australia, Canada, Germany, New Zealand and the US, is advising people to take four key steps to protect their devices.

People must “stay mainstream” by only using trusted app stores, “stay organised” by reviewing installed apps and permissions regularly, “stay in touch” by reporting suspicious files, and “stay safe” by checking shared files and links, it says.

The apps often mimic popular software, with some designed to appeal directly to victims.

Examples of software include “Tibet One” and “Audio Quran” apps, which support targets’ native languages and have been promoted in online forums frequented by intended users, as well as some apps imitating the likes of WhatsApp and Skype.

Data being collected is “almost certainly of value” to the Chinese government and could facilitate surveillance and harassment, cyber experts warn.

Civil society groups are also being targeted, according to the advisory.

The guidance was published jointly by the NCSC, the Australian Cyber Security Centre, the Canadian Centre for Cyber Security, the German Federal Intelligence Service, the German Federal Office for the Protection of the Constitution, the New Zealand National Cyber Security Centre, the US Federal Bureau of Investigation and the US National Security Agency.

It says: “Although BADBAZAAR and MOONSHINE have been observed targeting Uighur, Tibetan and Taiwanese individuals, there are other malware that target other minority groups in China. Citizens from co-sealing nations, in China and abroad, who are perceived to be supporting causes that threaten regime stability are almost certainly under threat from mobile malware such as BADBAZAAR and MOONSHINE.

“The capability to capture location, audio and photo data almost certainly provides the opportunity to inform future surveillance and harassment operations by providing real-time information on the target’s activity.”

By Press Association

More Technology News

See more More Technology News

Imagery of a Zilch payments card and a virtual card

Buy now pay later provider Zilch to launch first physical card

UK’s most EV-friendly city has been revealed by new research.

Cities with slowest EV charging times and least amount of chargers revealed

View of a VodafoneThree logo outside the firm's offices

Vodafone completes Three UK mega-merger to form ‘new force’ in mobile market

A hand holding a Monzo bank card and a mobile phone showing the Monzo app

Monzo annual profit surges as paying subscribers boost digital bank

Majestic British Airways Airbus A380 taking off from London Heathrow at sunset, amazing colors

UK airspace shake-up could slash journey times and cut flight delays for millions of passengers

File photo dated 30/05/25 of the saltmarsh at Abbotts Hall in Essex. Saltmarshes are 'significant' carbon stores, but are at risk from rising sea levels, new research reveals

UK's muddy saltmarshes vital to tackle climate change, report finds

Nigel Farage

Reform backs cryptocurrency tax cut as party receives first Bitcoin donations

Digital devices on office workplace table of young business woman

‘Young people and black workers at highest risk of workplace surveillance’

Debris from the Titan submersible, recovered from the ocean floor near the wreck of the Titanic, is unloaded from the ship Horizon Arctic at the Canadian Coast Guard pier in St. John's, Newfoundland, in June 2023

The shock household item discovered in 'sludge' of OceanGate sub wreckage

Google is facing a £25 billion legal claim in the UK, accusing the tech giant of abusing its dominant position in the online search advertising market

Google facing £25 billion legal claim over abuse of search advertising market

A hand holding a phone showing the Nvidia logo

Nvidia posts strong growth despite ongoing tariff challenges

Dinosaur fossils could hold the key to new cancer discoveries and influence future treatments for humans, scientists have said.

Dinosaur fossils with tumours could hold key to new cancer treatments for humans, scientists say

A SpaceX Starship spun out of control in a test flight

Elon Musk's SpaceX Starship spirals out of control before exploding in third consecutive mission failure

Some 13 mobile masts have been upgraded in four regions, with mobile networks now covering an area equivalent to thousands of football pitches

Rural Scots in four regions given ‘significant’ 4G coverage boost

Lord Peter Mandelson

UK and US should cooperate on AI to counter China ‘threat’, says Mandelson

An Adidas store on Oxford Street, central London

Hackers steal Adidas customer data in cyber attack