PULSE NAME
Weaponized Words: Uyghur Language Software Hijacked to Deliver Malware
WHITE AlienVault 2025-04-28 Modified: 2025-04-28
8
IOCs
LOW VOLUME
This analysis details a spearphishing campaign targeting senior members of the World Uyghur Congress (WUC) in March 2025. The attackers used a trojanized version of a legitimate Uyghur language text editor to deliver Windows-based malware for remote surveillance. While not technically advanced, the malware delivery was well-customized to reach the Uyghur community. This incident is part of a broader pattern of digital transnational repression against Uyghur diaspora by actors likely aligned with the Chinese government. The malware profiled systems, sent information to remote servers, and could load additional malicious plugins. The campaign demonstrates the ongoing digital threats facing exiled Uyghur communities and the exploitation of software meant to support marginalized cultures.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
UyghurEditPP trojan GheyretDetector backdoor
Indicators of Compromise (8)
All FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 70af9a31d4470502a39d71ca566d604317a5ecbf9181a64379c9ee761e2f95ab 2025-04-28
FileHash-SHA256 94a87dadeaac24bbc26c85d032b86a45cfd131516666e8e5d888f78986d1e993 2025-04-28
FileHash-SHA256 a9e76af3f3b04b9dd65e2e4dec8d5b00f8f67b420809da8b742651cc86e4270f 2025-04-28
FileHash-SHA256 d6874907d0e558cba614313c60b84c912b10ca3c539661a3885daaadb1cb2b2b 2025-04-28
URL https://tengri.ooguy.com/gheyret/Update 2025-04-28
hostname anar.gleeze.com 2025-04-28
hostname tengri.ooguy.com 2025-04-28
hostname wanar.gleeze.com 2025-04-28