CSIDB logo
Incident

East Turkestan Cultural Center

Incident posture

Attack window
Sep 2015
Location
China
Status
Historical
CIA posture
Available to members
Updated
2026-01-14 16:43

Linked entities

Victim
East Turkestan Cultural Center
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Chinese state-linked threat actors conducted cyber campaigns targeting the Uyghur diaspora through compromised websites and malicious infrastructure. The attackers deployed Android exploits, the Scanbox framework, and deceptive domains mimicking legitimate services to enable surveillance and data theft, including unauthorized access to Gmail accounts via OAuth. These operations facilitated extensive monitoring and exploitation of the minority group's digital activities.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The incident involved sustained cyber espionage campaigns targeting Uyghur diaspora communities and affiliated organizations, including entities such as the East Turkestan Cultural Center. Since at least 2019, attackers compromised at least 11 Uyghur and East Turkistan-related websites to deploy surveillance and exploitation tools against visitors. These websites were injected with unauthorized JavaScript code that enabled the profiling of visitors through the Scanbox framework, which collected system information, installed software details, and captured keystrokes. Mobile users running Android OS were specifically targeted via exploits delivering 64-bit ARM executables, while attackers also attempted to hijack Gmail accounts by abusing Google OAuth through malicious applications. Attacker infrastructure included doppelganger domains impersonating Google, the Turkistan Times, and the Uyghur Academy to facilitate credential theft and malware distribution.

The campaigns employed multiple attack vectors, including the Evil Eye surveillance framework and network traffic obfuscation techniques like IP address decimal notation conversion. Two distinct Chinese advanced persistent threat (APT) groups orchestrated these operations, leveraging compromised websites as strategic distribution points. Impacts included unauthorized access to sensitive communications, contact lists from compromised email accounts, and persistent surveillance of Uyghur activists’ online activities. Volexity’s analysis identified attacker infrastructure patterns and network signatures tied to these operations but did not observe specific containment measures by victim organizations. The operations formed part of a broader digital suppression effort against Uyghur communities, complementing physical surveillance and detention campaigns documented in Xinjiang.

Sources

Sources available to members: 1 source.

CSIDB