ETDA สำนักงานพัฒนาธุรกรรมทางอิเล็กทรอนิกส์
Electronic Transactions Development Agency
Report
Search
Home > List all groups > List all tools > List all groups using tool BadBazaar

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: BadBazaar

NamesBadBazaar
CategoryMalware
TypeBackdoor, Info stealer, Exfiltration
Description(Lookout) We named this malware family BadBazaar in response to an early variant that posed as a third-party app store titled “APK Bazar.” Bazar is a lesser known spelling of Bazaar.

Lookout has since acquired 111 unique samples of the BadBazaar surveillanceware dating back to late 2018. Over 70% of these apps were found in Uyghur-language communication channels within the second half of 2022.

The malware primarily masquerades as a variety of Android apps, such as battery managers, video players, radio apps, messaging apps, dictionaries, and religious apps. We also found instances of apps pretending to be a benign third-party app store for Uyghurs.
Information<https://www.lookout.com/blog/uyghur-surveillance-campaign-badbazaar-moonshine>

Last change to this tool card: 19 November 2022

Download this tool card in JSON format

All groups using tool BadBazaar

ChangedNameCountryObserved

APT groups

 Poison Carp, Evil EyeChina2018-Jun 2023X

1 group listed (1 APT, 0 other, 0 unknown)

Digital Service Security Center
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1227
E-mail [email protected]