Saturday, December 20, 2025
News

China-linked hackers target Tibetans ahead of Dalai Lama's 90th birthday in cyber espionage campaigns

SocialTwist Tell-a-Friend    Print this Page   COMMENT

Dharamshala (Himachal Pradesh) | August 5, 2025 8:16:03 PM IST
Individuals associated with China conducted two cyber espionage initiatives aimed at the Tibetan community in the weeks approaching His Holiness the Dalai Lama's 90th birthday on July 6, 2025, as revealed by recent research from the U.S.-based security firm Zscaler ThreatLabz and the Tibetan Computer Emergency Readiness Team (TibCERT), according to a report by Phayul.

The campaigns, named Operation GhostChat and Operation PhantomPrayers, employed counterfeit Tibet-related applications and websites to covertly install spyware on the devices of victims, facilitating the theft of confidential information, enabling remote monitoring, and allowing control over devices.

Researchers have indicated that these campaigns utilised various subdomains under niccenter[.]net to imitate trusted websites. Victims were enticed into downloading harmful software themed around Tibetan cultural activities, which triggered multi-stage infection processes that deployed Gh0st RAT or PhantomNet (SManager), spyware tools frequently associated with groups backed by the Chinese state.

In Operation GhostChat, attackers infiltrated a legitimate Tibetan charity's website, substituting a link about the Dalai Lama's upcoming birthday with one that directed users to a deceptive lookalike site. This fraudulent site presented a so-called "Tibetan version" of a secure messaging application, which disguised the installation of Gh0st RAT. This malware was capable of logging keystrokes, taking screenshots, activating webcams, recording audio, and extracting files, as reported by Phayul.

Operation Phantom Prayers featured a counterfeit "Global Birthday Check-in" application that displayed an interactive map for sending good wishes to the Dalai Lama. Despite its innocent appearance, the app secretly deployed PhantomNet spyware, permitting attackers to download further malicious tools and steal sensitive data.

Security analysts describe this as the most recent occurrence in a series of "watering hole" attacks, which strategically compromise websites frequented by a specific target community, executed against the Tibetan diaspora. Similar tactics have previously been employed by Chinese-affiliated groups such as EvilBamboo, Evasive Panda, and TAG-112, according to the Phayul report.

"Considering the victimology and malware utilised in both operations, ThreatLabz attributes Operation GhostChat and Operation PhantomPrayers to cyber espionage teams supported by the Chinese state," the report affirmed, as referenced by the Phayul report.

Cybersecurity professionals caution that such initiatives are likely to persist, especially around significant Tibetan cultural or political occasions, when online activity is at its highest. (ANI)

 
  LATEST COMMENTS ()
POST YOUR COMMENT
Comments Not Available
 
POST YOUR COMMENT
 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
 
MORE WORLD NEWS
PM Modi's connect with Putin, Zelenskyy ...
Former Pak PM Imran Khan, wife Bushra Bi...
Justice Department says 'no political re...
Nepal Interim PM calls on people to gear...
Former Indian envoys warn of anarchy in ...
India shows how tradition, modern scienc...
More...
 
INDIA WORLD ASIA
Man arrested for smuggling banned Codein...
Delhi court says protest turned 'unruly'...
Haryana Police conducts raids on 900+ lo...
Assam Tragedy: Rajdhani Express derails ...
'Attack on working class': Pawan Khera s...
WB: People gather at Taherpur Netaji Par...
More...    
 
 Top Stories
Signify Lights up Bangalore: Streng... 
BMW presents the sixth edition of K... 
Chief Selector Agarkar arrives to B... 
"Govt is running away from discussi... 
Union Minister Giriraj Singh attend... 
Tilak Varma wins 'Impact Player of ... 
"Over 1 lakh EVs registered since B... 
LegalEdge Delivers Big in AILET 202...