Spyware accessing phone audio and cameras for data ‘of use to China’, NCSC warns

9 April 2025, 00:04

Person in yellow coat using smartphone on a train
Male person using smartphone while traveling by train mobile phone in hands close up. Picture: PA

The apps inside legitimate software in a technique known as trojanising, cyber experts warn.

Uighur, Tibetan and Taiwanese communities across the world are being targeted by spyware apps combing data likely to be of value to China, UK cyber experts have warned.

Malicious software dubbed MOONSHINE and BADBAZAAR is accessing microphones, cameras, messages, photos and location data without users being aware, GCHQ’s National Cyber Security Centre (NCSC) said.

The apps hide inside legitimate software in a technique known as trojanising, and are being used specifically to target individuals internationally who are linked to issues considered by Beijing to pose a threat to its security, experts warn.

In new guidance, the NCSC, along with agencies in Australia, Canada, Germany, New Zealand and the US, is advising people to take four key steps to protect their devices.

BADBAZAAR AND MOONSHINE collect data which would almost certainly be of value to the Chinese state

NCSC and international partners

People must “stay mainstream” by only using trusted app stores, “stay organised” by reviewing installed apps and permissions regularly, “stay in touch” by reporting suspicious files, and “stay safe” by checking shared files and links, it says.

The apps often mimic popular software, with some designed to appeal directly to victims.

Examples of software include “Tibet One” and “Audio Quran” apps, which support targets’ native languages and have been promoted in online forums frequented by intended users, as well as some apps imitating the likes of WhatsApp and Skype.

Data being collected is “almost certainly of value” to the Chinese government and could facilitate surveillance and harassment, cyber experts warn.

Civil society groups are also being targeted, according to the advisory.

The guidance was published jointly by the NCSC, the Australian Cyber Security Centre, the Canadian Centre for Cyber Security, the German Federal Intelligence Service, the German Federal Office for the Protection of the Constitution, the New Zealand National Cyber Security Centre, the US Federal Bureau of Investigation and the US National Security Agency.

It says: “Although BADBAZAAR and MOONSHINE have been observed targeting Uighur, Tibetan and Taiwanese individuals, there are other malware that target other minority groups in China. Citizens from co-sealing nations, in China and abroad, who are perceived to be supporting causes that threaten regime stability are almost certainly under threat from mobile malware such as BADBAZAAR and MOONSHINE.

“The capability to capture location, audio and photo data almost certainly provides the opportunity to inform future surveillance and harassment operations by providing real-time information on the target’s activity.”

By Press Association

More Technology News

See more More Technology News

Medical records report and stethoscope. Medical concept. Medical records report and stethoscope. Medical concept.

Half a million UK GP records to be accessed by Chinese researchers

The new WhatsApp chat feature

WhatsApp to message users about protecting themselves from scams

Leader of the House of Commons Lucy Powell leaves Downing Street in October 2024

Minister’s hacked X account promotes ‘House of Commons cryptocurrency’ scam

Trump

‘Severe strain’ on tech supply chains will cause more price rises in electronics

Close up of a pair of hands using and playing with a PS5 handset

Sony raises PlayStation 5 prices in UK and Europe

Facebook chief executive Mark Zuckerberg in Dublin

Meta faces landmark trial which could break up its tech empire

A message on an iPhone

Government’s encryption row with Apple ‘really strange’, expert says

Scientists have grown teeth in the lab for the first time

Scientists grow human teeth in the lab for the first time - in 'revolution for dentistry'

X logo

Data watchdog to investigate X’s Grok AI tool

Doctor using AI algorithm and machine learning to detect pneumonia

AI could lead to patient harm, researchers suggest

Elon Musk, CEO of Tesla and senior advisor to the president of the United States, has frozen Tesla sales in China.

Elon Musk freezes Tesla orders to China as Trump's trade war continues

Nearly a quarter of children spend more than four hours a day on an internet-enabled device, a survey for the Children’s Commissioner has suggested.

Nearly quarter of children spend more than four hours a day on devices

A laptop user with their hood up

Four in 10 UK businesses hit by cyber attack or breach in the last year

The remote-controlled mine plough system Weevil being put through its paces

Minefield-clearing robot to be trialled for British Army front lines

Elon Musk 'rage quits' favourite video game after being ‘cyber-bullied’ by players

Elon Musk 'rage quits' favourite video game after being ‘cyber-bullied’ by players

Exclusive
A video game which touts itself as an "incest and non-consensual sex" simulator has been banned in the UK

Home Secretary hails victory for LBC after vile rape and incest game pulled from download in UK