• Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
MUST READ

IT Worker arrested for selling access in $100M PIX cyber heist

 | 

New Batavia spyware targets Russian industrial enterprises

 | 

Taiwan flags security risks in popular Chinese apps after official probe

 | 

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

 | 

Hunters International ransomware gang shuts down and offers free decryption keys to all victims

 | 

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 52

 | 

Security Affairs newsletter Round 531 by Pierluigi Paganini – INTERNATIONAL EDITION

 | 

North Korea-linked threat actors spread macOS NimDoor malware via fake Zoom updates

 | 

Critical Sudo bugs expose major Linux distros to local Root exploits

 | 

Google fined $314M for misusing idle Android users' data

 | 

A flaw in Catwatchful spyware exposed logins of +62,000 users

 | 

China-linked group Houken hit French organizations using zero-days

 | 

Cybercriminals Target Brazil: 248,725 Exposed in CIEE One Data Breach

 | 

Europol shuts down Archetyp Market, longest-running dark web drug marketplace

 | 

Kelly Benefits data breach has impacted 550,000 people, and the situation continues to worsen as the investigation progresses

 | 

Cisco removed the backdoor account from its Unified Communications Manager

 | 

U.S. Sanctions Russia's Aeza Group for aiding crooks with bulletproof hosting

 | 

Qantas confirms customer data breach amid Scattered Spider attacks

 | 

CVE-2025-6554 is the fourth Chrome zero-day patched by Google in 2025

 | 

U.S. CISA adds TeleMessage TM SGNL flaws to its Known Exploited Vulnerabilities catalog

 | 
  • Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
  • Home
  • Intelligence
  • Security
  • China replies to Hong Kong protests with spyware, MITM and censorship

China replies to Hong Kong protests with spyware, MITM and censorship

Pierluigi Paganini October 02, 2014

Security experts speculate that the Chinese government is using mobile spyware, MITM attacks and Internet monitoring to control Hong Kong protesters.

In the last days I published the news regarding a spyware used to spy on activists in Hong Kong, a Fake Occupy Central app is targeting the smartphones of the activists belonging to the Occupy Central pro-democracy movement. The malicious app  has circulated online claiming to be an instrument to coordinate the members of the Occupy Central pro-democracy movement. The spyware is disguised as an Android App, dubbed Code4HK, designed by a group of coders trying to improve government transparency in Hong Kong.

“No one from the Code4hk community has done any application on OC at the moment nor sent the message out.” Code4HK in an official statement.

It’s a shared opinion that  the Chinese government might be using smartphone apps to spy on pro-democracy protesters in Hong Kong, the suspect is confirmed by the analysis made by the US.security firm Lacoon Mobile Security. The company speculated that the malicious app might be the first spyware for iOS created by a Chinese government entity.

“The fact that this attack is being used against protesters and is being executed by Chinese-speaking attackers suggests it’s first iOS trojan linked to Chinese government cyber activity.” state the researchers.

Lacoon Mobile Security detected two similar “malicious, fake” apps that seem to be related, respectively target Apple smartphone and Android devices, this circumstance is another element that suggests investigators the involvement of a government.

The identities of the targeted individuals and information gathered on the C&C servers used in the malicious campaign lead experts to believe that the malware was spread by state-sponsored hackers.

 “The identity of the victims, as well as data from the CnC (Command and Control) servers lead us to believe that the Chinese Government are behind the attack. This is also a very advanced mRAT that is undoubtedly being backed by a nation state.” states the blog post from Lacoon.

China has great cyber capabilities, for this reason is not surprising that the government of Beijing would have used a similar strategy to track the protesters in Hong Kong, of course the Chinese authorities have denied any involvement is the case.

The software used to infect mobile devices is known as Xsser mRAT, or multidimensional requirements analysis tool, as explained by the company.

“The Xsser mRAT represents a fundamental shift by nation-state cybercriminals from compromising traditional PC systems to targeting mobile devices,”

hong kong spyware

As explained by the team at Lacoon the iOS device needs to be jailbroken in order to be infected, but the researchers haven’t uncovered information regarding the attack chain.

The diffusion of spyware isn’t the unique measure adopted by the Chinese Government against protesters in Hong Kong, China also Restricted in China the access to the Yahoo! Inc.’s (YHOO) main website to block the flow of information amid student-led protests in Hong Kong.

The Greatfire.org, a group that monitors Internet censorship in China, confirmed that www.yahoo.com site was inaccessible in some parts of the country. The group also speculated on a possible “man-in-the-middle attack,”against users accessing Yahoo’s servers. Something similar was observed a few weeks ago on Gmail services accessed from mainland China.

“Yahoo’s search page had remained free of restrictions in China even after Google Inc.’s (GOOG)website was blocked and access to its Gmail service was restricted ahead of the 25th anniversary of the June 4, 1989 Tiananmen Square crackdown. China has sought to control information emanating from Hong Kong, where student demonstrators have protested since Sept. 26 to demand free elections of their city leader.”  reported Bloomberg on the case.

Yahoo’s mail and news services remained available in China yesterday, while the access to Yahoo’s Hong Kong, Taiwan and Canada portals from within China was also disrupted.

Stay tuned for further news.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Yahoo, Hong Kong)

[adrotate banner=”13″]


facebook linkedin twitter

Android Censorship China Hong Kong iOS jailbroken Lacoon MITM mobile Occupy Central spyware Xsser mRAT

you might also like

Pierluigi Paganini July 08, 2025
IT Worker arrested for selling access in $100M PIX cyber heist
Read more
Pierluigi Paganini July 07, 2025
Taiwan flags security risks in popular Chinese apps after official probe
Read more

leave a comment

newsletter

Subscribe to my email list and stay
up-to-date!

    recent articles

    IT Worker arrested for selling access in $100M PIX cyber heist

    Cyber Crime / July 08, 2025

    New Batavia spyware targets Russian industrial enterprises

    Uncategorized / July 07, 2025

    Taiwan flags security risks in popular Chinese apps after official probe

    Security / July 07, 2025

    U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

    Hacking / July 07, 2025

    Hunters International ransomware gang shuts down and offers free decryption keys to all victims

    Cyber Crime / July 06, 2025

    To contact me write an email to:

    Pierluigi Paganini :
    pierluigi.paganini@securityaffairs.co

    LEARN MORE

    QUICK LINKS

    • Home
    • Cyber Crime
    • Cyber warfare
    • APT
    • Data Breach
    • Deep Web
    • Digital ID
    • Hacking
    • Hacktivism
    • Intelligence
    • Internet of Things
    • Laws and regulations
    • Malware
    • Mobile
    • Reports
    • Security
    • Social Networks
    • Terrorism
    • ICS-SCADA
    • POLICIES
    • Contact me

    Copyright@securityaffairs 2024

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities...
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
    Non-necessary
    Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
    SAVE & ACCEPT