CSIDB logo
Threat actor

Evil Eye

Attribution profile

Type
Nation State
Location
China
Known incidents
14 incidents
First seen
2013-01-01
Last seen
2019-08-01
Updated
2026-08-01 08:57
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Evil Eye is a threat actor alias that has been linked to Chinese state‑sponsored APT groups operating from China. The actor is primarily known for conducting prolonged surveillance and exploitation campaigns against the Uyghur diaspora, a Muslim minority ethnic group originating from the Xinjiang Uyghur Autonomous Region. Public reporting attributes these operations to Chinese APT groups and describes the activity as state‑sponsored cyber espionage aimed at monitoring, data theft and intelligence gathering against the targeted minority community. The strategic objectives described in the sources are consistently espionage‑focused, involving the collection of emails, contact lists, device information and location data to support broader monitoring and suppression efforts, with no indication of financially motivated or disruptive intent reported in the material.

The actor’s tactics, techniques and procedures, as documented in the Volexity analysis and related incident summaries, rely heavily on web‑based initial access through compromised Uyghur‑focused websites such as the Uyghur Academy, the Turkistan Times and the World Uyghurs Writers Union. These sites are weaponized with the Scanbox profiling and exploitation framework to profile visitors and deliver malicious payloads. A prominent initial‑access vector involves the deployment of Android exploits that deliver 64‑bit ARM executables to mobile users, enabling data collection from compromised devices. Evil Eye also employs doppelganger domains that mimic legitimate services—including Google, the Turkistan Times and the Uyghur Academy—to lure victims into divulging credentials. Credential theft is further facilitated through the abuse of Google OAuth, where fraudulent applications masquerading as legitimate services (e.g., “Uyghur Media Email Group”) are used to hijack Gmail accounts and exfiltrate email and contact data. Infrastructure observed in the campaigns includes iframes loading malicious URLs from IP addresses and domains such as 103.43.18.243, 182.61.171.167, 182.61.173.209, 45.76.209.90, google‑analysis.info, turkistantlmes.com and akademlye.org, accompanied by a specific network signature designed to detect the Evil Eye Android malware beacon. Notable campaigns described in the sources include a series of compromised Uyghur and East Turkistan websites dating back to at least 2013, with intensified activity noted in 2015 and a resurgence in 2019 that leveraged Scanbox, Android exploits, doppelganger domains and OAuth abuse to conduct extensive surveillance of the Uyghur diaspora across multiple vectors. These operations have been characterized as coordinated efforts by multiple Chinese APT groups to maintain persistent access and gather intelligence on the targeted population.

Incidents

Attributed incidents are available to members.

14 incidents
CSIDB