Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Far from the pitch, David Beckham remains soccer’s biggest star

Singer and producer dies in helicopter crash

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » China-based APTS will deploy fake Dalai Lama apps to spy on Tibetan communities
Celebrities

China-based APTS will deploy fake Dalai Lama apps to spy on Tibetan communities

By July 24, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 24, 2025Ravi LakshmananCyber Spy/Malware

The Tibetan community was targeted by Chinese and Nexus cyberspy groups as part of two campaigns run last month ahead of the Dalai Lama’s 90th birthday on July 6, 2025.

Multi-stage attacks are codenamed Operation GhostChat and Phantomprayers Operations by Zscaler Threatlabz.

“The attackers breached a legal website, redirected users via malicious links, and eventually installed a GH0st rat or PhantomNet (aka Smanager) backdoor on the victim system,” security researchers Sudeep Singh and Roy Tay said in a report Wednesday.

This is not the first time a Chinese threat actor has resorted to a hole attack (aka strategic web compromise). This is a technology in which enemies enter websites where certain groups frequently visit and infect malware.

Cybersecurity

For the past two years, hacking groups such as Evilbamboo, Evasive Panda and Tag-112 have all relied on an approach to targeting the Tibetan diaspora, with the ultimate goal of gathering sensitive information.

Operation Ghostchat

The latest set of attacks observed by Zscaler involves compromise on web pages to replace links pointing to “TibetFund”[.]org/90thbirthday “Invalid Version (” thedalailama90.niccenter[.]net”).

The original webpage is designed to send messages to Dalai Lama, but the replica page will be downloaded from “tbelement.niccenter” and add the option to send the encrypted message to the spiritual reader.[.]A secure chat application named Net “Telement. It claims to be an element of the Tibetan version.

Hosted on the website is a background version of open source encrypted chat software that contains malicious DLLs sideloaded to launch Gh0st Rat, a remote access trojan widely used by various Chinese hacking groups. The web page also contains JavaScript code designed to collect visitor IP addresses and user agent information and portray details to threat actors via HTTP POST requests.

Phantom Operation

Gh0st Rat is a fully-dished malware that supports file manipulation, screen capture, clipboard content extraction, webcam video recording, keylogs, audio recording and playback, process manipulation, and remote shells.

The second campaign, Operation Phantomrayers, is known to utilize another domain, “hhthedalailama90.niccenter.”[.]The Net, “Distribute Fony” 90th birthday global check-in “App (“dalailamacheckin.exe”, called Phantom Player”) will display an interactive map when opened and encourage victims to “send a blessing.”

Cybersecurity

However, malicious features use a backdoor that establishes contact with a command and control (C2) server via TCP using DLL sideload technology, and launches a backdoor that establishes additional plug-in (C2) servers for running on complex machines.

“PhantomNet can be configured to work only within a certain time or a few days, but this feature is not enabled in the current sample,” the researchers said. “PHANTOMNET used modular plug-in DLLs, AES encrypted C2 traffic, and configurable timing operations to stealthly manage compromised systems.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article£30 million for green fuels and technology for decarbonized transport
Next Article Do you have a pen test once a year? no. It’s time to build offensive SOCs

Related Posts

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026

Katie Holmes, Kiki Palmer, etc.

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Far from the pitch, David Beckham remains soccer’s biggest star

Singer and producer dies in helicopter crash

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

Tullamarines cover Fleetwood Mac with ‘Like a Version’

Trending Posts

Singer and producer dies in helicopter crash

June 14, 2026

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

June 14, 2026

Tullamarines cover Fleetwood Mac with ‘Like a Version’

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.