Spyware accessing phone audio and cameras for data ‘of use to China’, NCSC warns

9 April 2025, 00:04

Person in yellow coat using smartphone on a train
Male person using smartphone while traveling by train mobile phone in hands close up. Picture: PA

The apps inside legitimate software in a technique known as trojanising, cyber experts warn.

Uighur, Tibetan and Taiwanese communities across the world are being targeted by spyware apps combing data likely to be of value to China, UK cyber experts have warned.

Malicious software dubbed MOONSHINE and BADBAZAAR is accessing microphones, cameras, messages, photos and location data without users being aware, GCHQ’s National Cyber Security Centre (NCSC) said.

The apps hide inside legitimate software in a technique known as trojanising, and are being used specifically to target individuals internationally who are linked to issues considered by Beijing to pose a threat to its security, experts warn.

In new guidance, the NCSC, along with agencies in Australia, Canada, Germany, New Zealand and the US, is advising people to take four key steps to protect their devices.

People must “stay mainstream” by only using trusted app stores, “stay organised” by reviewing installed apps and permissions regularly, “stay in touch” by reporting suspicious files, and “stay safe” by checking shared files and links, it says.

The apps often mimic popular software, with some designed to appeal directly to victims.

Examples of software include “Tibet One” and “Audio Quran” apps, which support targets’ native languages and have been promoted in online forums frequented by intended users, as well as some apps imitating the likes of WhatsApp and Skype.

Data being collected is “almost certainly of value” to the Chinese government and could facilitate surveillance and harassment, cyber experts warn.

Civil society groups are also being targeted, according to the advisory.

The guidance was published jointly by the NCSC, the Australian Cyber Security Centre, the Canadian Centre for Cyber Security, the German Federal Intelligence Service, the German Federal Office for the Protection of the Constitution, the New Zealand National Cyber Security Centre, the US Federal Bureau of Investigation and the US National Security Agency.

It says: “Although BADBAZAAR and MOONSHINE have been observed targeting Uighur, Tibetan and Taiwanese individuals, there are other malware that target other minority groups in China. Citizens from co-sealing nations, in China and abroad, who are perceived to be supporting causes that threaten regime stability are almost certainly under threat from mobile malware such as BADBAZAAR and MOONSHINE.

“The capability to capture location, audio and photo data almost certainly provides the opportunity to inform future surveillance and harassment operations by providing real-time information on the target’s activity.”

By Press Association

More Technology News

See more More Technology News

A woman's hand on a laptop keyboard

UK and allies expose Russian cyber attacks on logistics firms aiding Ukraine

Marks and Spencer signage

Slow recovery ‘appropriate’ to ensure M&S is secure after cyber attack – experts

A shopper walks through a Marks & Spencer store

Marks & Spencer hack: When will the retailer be back to normal?

Alphabet chief executive Sundar Pichai on stage

Google in ‘tough position’ as it balances AI advances and advertising revenue

Alphabet chief executive Sundar Pichai speaking on stage

The key announcements from Google I/O

Close-up of a smartphone showing the Google app page in the App Store.

Google launches fully AI-powered search engine despite concerns over misinformation and climate impact

TV gardener Alan Titchmarsh warned that the Uk's potato crops were in "grave danger" due to the emergence of the insect in the last two years

UK potato crops in 'grave danger' as Alan Titchmarsh warns of 'savage' threat to food security

Woman doing grocery shopping at the supermarket and reading food labels

Food distributor for supermarkets hit by ransomware attack

Treasury Committee

NatWest boss says AI is ‘addition’ to human jobs rather than replacement

People walk past cows that are wearing GPS collars while grazing on Midsummer Common in Cambrige

Cambridge cows get GPS collars to stop them from falling into river

A mysterious object in space has been sending an ‘unexpected’ pulsing signal to Earth that is ‘unlike anything ever seen before’, as scientists say they can’t rule out aliens.

Mystery space object sending ‘inexplicable’ pulsing signal to Earth as Nasa scientists ‘can’t rule out aliens’

Group of people holding plaques and signs

Government defeated for third time in Lords over copyright protection against AI

Lines of code on a computer screen

Solicitors criticise ‘antiquated’ Legal Aid Agency IT system after cyber attack

The Meta AI app page in the App Store on a smartphone screen

More than third of UK consumers now use AI to shop – survey

Scientists took months to develop gene therapy for baby KJ Muldoon to treat his rare genetic disease.

Baby with rare genetic disease receives personalised gene therapy in world first

A UK Driving Licence shake-up is coming this summer

Major driving licence change to launch this summer - affecting up to 50 million Brits