ZeroHour
CyberScooppublished ()ingested @jeffstone500

A cyber-espionage effort against Tibetan leaders leveraged known Android, iOS vulnerabilities

criticalVulnerability exploited in the wildimportance 60
Full article838 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Citizen Lab says the spyware campaign involved attackers who posed as journalists, Amnesty International researchers, nongovernmental organization workers through May 2019.

Tibet
The Palcho Monastery in the town of Gyangzê, Tibet, with the Gyantse Dzong fortress on the ridge behind. (Getty Images)

Hackers aimed to infect mobile phones belonging to senior members of Tibetan groups, including people who worked directly for the Dalai Lama, as well as lawmakers in Tibet’s parliament, according to new findings from a team of researchers at the University of Toronto.

The digital rights group Citizen Lab on Tuesday detailed an apparent cyber-espionage effort which involved attackers posing as journalists, Amnesty International researchers, nongovernmental organization workers and other faked identities to send malicious links in a WhatsApp conversation. Researchers observed the campaign, dubbed Poison Carp, between November 2018 and May 2019.

Hackers relied on eight Android browser vulnerabilities, Android spyware, a single iOS exploit chain (a combination of malicious actions allowing hackers to achieve a goal) and iOS spyware. None of the attacks utilized zero-day exploits, the name given to hacking tools that take advantage of never-disclosed vulnerabilities.

None of the intrusion attempts detected here were successful, but at least one person reported clicking on the malicious link, Citizen Lab said. Running up-to-date software on their phones was apparently enough to help targets avoid infection.

Some of the malicious tools also were noted in previous research detailing similar attacks against China’s Uighur population reported by experts on Google’s Project Zero team, and in other findings by the security firm Volexity. Hackers, by infiltrating a phone, could have collected location information, message details, leveraged the phone’s camera and microphone and mapped contacts.

Those attacks were later attributed to China and, although Citizen Lab does not speculate who may be behind the effort revealed Tuesday, the Chinese government for years has dedicated vast surveillance efforts to gather information about both the Tibetan and Uighur populations.

“Based on these similarities, it is likely the campaigns were conducted by the same operator, or a coordinated group of operators, who have an interest in the activities of ethnic minority groups that are considered sensitive in the context of China’s security interests,” Citizen Lab researchers wrote.

Along with providing insight into international spying tactics, this research also provides the latest evidence that iOS software is more vulnerable than many security practitioners realized until very recently. The zero-day broker Zerodium in September noted that the most advanced Android exploits now are worth more than their iOS counterparts, in part because of the popularity of iOS hacking tools.

More Scoops

This aerial photograph shows demonstrators and students as they gather in front of Serbia’s Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…

Apple iOS update screen is seen displayed on a phone screen in this illustration photo taken in Krakow, Poland on Sept. 17, 2025. (Photo by Jakub Porzycki/NurPhoto)

DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses

Darksword exploit kit
(Getty Images)

Second iOS exploit kit now in use by suspected Russian hackers

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/tibet-citizen-lab-spyware-espionage/