Sunday, December 21, 2025
News

China-linked hackers target Tibetans ahead of Dalai Lama's 90th birthday in cyber espionage campaigns

SocialTwist Tell-a-Friend    Print this Page   COMMENT

Dharamshala (Himachal Pradesh) | August 5, 2025 8:16:03 PM IST
Individuals associated with China conducted two cyber espionage initiatives aimed at the Tibetan community in the weeks approaching His Holiness the Dalai Lama's 90th birthday on July 6, 2025, as revealed by recent research from the U.S.-based security firm Zscaler ThreatLabz and the Tibetan Computer Emergency Readiness Team (TibCERT), according to a report by Phayul.

The campaigns, named Operation GhostChat and Operation PhantomPrayers, employed counterfeit Tibet-related applications and websites to covertly install spyware on the devices of victims, facilitating the theft of confidential information, enabling remote monitoring, and allowing control over devices.

Researchers have indicated that these campaigns utilised various subdomains under niccenter[.]net to imitate trusted websites. Victims were enticed into downloading harmful software themed around Tibetan cultural activities, which triggered multi-stage infection processes that deployed Gh0st RAT or PhantomNet (SManager), spyware tools frequently associated with groups backed by the Chinese state.

In Operation GhostChat, attackers infiltrated a legitimate Tibetan charity's website, substituting a link about the Dalai Lama's upcoming birthday with one that directed users to a deceptive lookalike site. This fraudulent site presented a so-called "Tibetan version" of a secure messaging application, which disguised the installation of Gh0st RAT. This malware was capable of logging keystrokes, taking screenshots, activating webcams, recording audio, and extracting files, as reported by Phayul.

Operation Phantom Prayers featured a counterfeit "Global Birthday Check-in" application that displayed an interactive map for sending good wishes to the Dalai Lama. Despite its innocent appearance, the app secretly deployed PhantomNet spyware, permitting attackers to download further malicious tools and steal sensitive data.

Security analysts describe this as the most recent occurrence in a series of "watering hole" attacks, which strategically compromise websites frequented by a specific target community, executed against the Tibetan diaspora. Similar tactics have previously been employed by Chinese-affiliated groups such as EvilBamboo, Evasive Panda, and TAG-112, according to the Phayul report.

"Considering the victimology and malware utilised in both operations, ThreatLabz attributes Operation GhostChat and Operation PhantomPrayers to cyber espionage teams supported by the Chinese state," the report affirmed, as referenced by the Phayul report.

Cybersecurity professionals caution that such initiatives are likely to persist, especially around significant Tibetan cultural or political occasions, when online activity is at its highest. (ANI)

 
  LATEST COMMENTS ()
POST YOUR COMMENT
Comments Not Available
 
POST YOUR COMMENT
 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
 
MORE WORLD NEWS
Taiwan boosts public security after dead...
Hamdan bin Zayed attends group wedding o...
'We set a really bad example as a nation...
Dubai reinforces status as global hub fo...
US seizes second oil tanker off the coas...
Earthquake of magnitude 3.3 strikes Paki...
More...
 
INDIA WORLD ASIA
'Conspiracy is being hatched to mislead ...
Radicalisation...no true Islam in Bangla...
'Modi govt admires Godse, hates Gandhi':...
BRO speeds up work on Rajouri-Surankote ...
J-K: Sonamarg witnesses fresh spell of s...
Gurugram Police solve blind murder case,...
More...    
 
 Top Stories
UAE signs agreement with UNHCR to s... 
"Conspiracy is being hatched to mis... 
1st T20I: India Women win toss, opt... 
"Love hasn't aged a bit": Director ... 
Two more arrested in connection wit... 
Do we need constitutional approval ... 
"Momentous for state in our stride ... 
Venezuela accuses US of 'internatio...