As the Dalai Lama marked his 90th birthday, China-linked hackers launched cyberattacks aimed at Tibetans. These state-sponsored operations used fake apps and cloned websites to deploy spyware.

Researchers say the campaigns used culturally themed lures to trick users into installing malware. Victims unknowingly downloaded apps that carried Gh0st RAT or PhantomNet—tools often linked to Chinese cyber-espionage groups.

Fake Websites and “Cultural” Apps

Hackers used subdomains of niccenter[.]net to host decoy platforms. These sites mimicked legitimate Tibetan websites and tricked users into downloading spyware under the guise of celebratory tools.

The first attack, named “Operation GhostChat,” copied a real Tibetan charity website. The fake site offered a Tibetan version of a secure messaging app. Users who downloaded it actually installed Gh0st RAT.

This spyware gave hackers access to victims’ microphones, webcams, keyboards, and files. It also allowed remote control over infected devices.

The second attack, “Operation PhantomPrayers,” featured a fake “Global Birthday Check-in” app. The interactive map let users send greetings to the Dalai Lama. In reality, it delivered PhantomNet spyware, which harvested sensitive data and installed further malware.

Attribution and Intent

A joint report by Zscaler ThreatLabz and the Tibetan Computer Emergency Readiness Team (TibCERT) attributes both campaigns to Chinese state-sponsored groups. The report highlights the malware’s structure, target selection, and distribution methods as key indicators of state involvement.

TibCERT operates under the Tibet Action Institute, a U.S.-based NGO. Analysts say the group has connections to democratic government organizations such as USAID and the U.S. State Department.

Broader Espionage Pattern

Researchers classify these operations as “watering hole” attacks. This technique involves infecting websites frequently visited by a specific group. Cybersecurity experts say similar methods have been used by known Chinese-linked actors like EvilBamboo, Evasive Panda, and TAG-112.

These new campaigns continue a pattern of using targeted malware to monitor and manipulate politically sensitive communities.


Conclusion

The China spyware Dalai Lama campaigns reveal a troubling fusion of cultural manipulation and cyber espionage. By exploiting trust and significant cultural moments, hackers gained deep access to the Tibetan community. These attacks show how digital threats can carry political motives and long-term consequences.


0 responses to “China Spyware Dalai Lama Attacks Target Tibetan Community”