Skip to content
Droid Tools
Home
About UsContact
Editorial PolicyReview Policy
Privacy PolicyCookie PolicyTerms & Conditions
⌘K
Search
FacebookX (Twitter)InstagramThreadsBlueskyTikTokYouTubeRedditTelegramRSS Feed
Trending:
Galaxy S26•Pixel 10•Android 16•Nothing OS•Gemini AI•Smartwatches•Tech Deals•Latest Reviews•How-to Guides
Droid Tools

Droid Tools covers the latest Android news, device reviews, app updates, and OS guides. Stay informed with hands-on coverage from mobile tech experts.

Explore

  • News
  • Apps
  • OS
  • Phones
  • Reviews

Legal & Info

  • About Us
  • Contact
  • Editorial Policy
  • Review Policy
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Affiliate Disclosure
  • Disclaimer
  • HTML Sitemap
  • XML Sitemap
© 2026 Droid Tools. All rights reserved.
Home/Apps/BadBazaar Android malware linked to Chinese cyberspies
Apps

BadBazaar Android malware linked to Chinese cyberspies

Robert Haba
Nov 18, 20223 min read
Robert Haba
Robert Haba
Founder · Editor-in-Chief
Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.
X
Profile →
BadBazaar malware android apps
0%
Share on XFacebookBluesky
Follow on Google
Advertisement
Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source

Key Takeaways

Automated Editorial Synthesis
AI Overview
  • Call logs with geolocation data
  • Exfiltrate files or databases
  • Access folders of high-interest (images, IM app logs, chat history, etc.)

Unknown Android spyware called “BadBazaar” has been found to target China’s ethnic and religious minorities, particularly the Uyghurs in Xinjiang.

Due to their cultural divergence from traditional eastern Chinese values, the central Chinese government has subjected the 13 million-strong Uyghur Muslim minority to extreme oppression.

Advertisement

The new spyware was originally discovered by MalwareHunterTeam and linked to Bahamut in VirusTotal detections.

BadBazaar spyware

Lookout performed more investigation on the malware and discovered that it was brand-new spyware that was being used by APT15, a state-sponsored hacking outfit, in its 2020 attacks against Uyghurs (aka “Pitty Tiger).

Lookout also noticed a second campaign employing updated versions of the spyware known as “Moonshine,” which CitizenLab first came up in 2019 when using it against Tibetan organizations.

Advertisement
BadBazaar malware

Since 2018, the BadBazaar spyware has promoted itself on communication channels frequented by the targeted ethnic group by infecting Uyghurs using at least 111 different apps.

You May Also Like
Recommended
1

Android 17 quietly blocks apps from detecting Developer Mode status

android 17 developer mode
2

Samsung shutting down Quick Measure and AR Doodle apps in 2026

samsung ar doogle
3

Google Photos integration comes to Gemini Spark for Pro and Ultra users

gemini spark

The impersonated apps fall under a variety of categories, including dictionaries, tools for religious practice, battery savers, and media players.

Since Google Play, Android’s official app store, has never seen any record of these apps, they are most likely distributed through rogue websites or unreliable third-party stores.

It’s interesting that there is only one instance of an iOS app on the Apple App Store that communicates with the malicious C2, but it merely sends the device UDID and doesn’t have spyware functionality.

Advertisement

BadBazaar’s data-collecting capabilities include the following:

  • Precise location
  • List of installed apps
  • Call logs with geolocation data
  • Contacts list
  • SMS
  • Complete device info
  • WiFi info
  • Phone call recording
  • Take pictures
  • Exfiltrate files or databases
  • Access folders of high-interest (images, IM app logs, chat history, etc.)

Looking into the C2 infrastructure, which exposes some of the admin panels and the GPS coordinates of test devices due to errors, Lookout analysts found connections to the Chinese defense contractor Xi’an Tian He Defense Technology.

BadBazaar malware apps
Only a few of the BadBazaar apps promoted to Uyghurs (Lookout)
BadBazaar malware infected apps
Sample of apps carrying Moonshine spyware (Lookout)

Moonshine variants

Lookout researchers began to discover a new operation in July 2022 that uses 50 apps to push users new versions of the “Moonshine” spyware.

These programs are advertised on Telegram channels for Uyghur speakers, where dishonest users recommend them to other users as reliable software.

Examples of programs that contain the spyware Moonshine (Lookout)
The creators of the more recent virus have added additional modules to increase the tool’s capacity for spying, and it is still modular.

Network activity, IP addresses, hardware details, and other information are among the data that Moonshine takes from hacked devices.

BadBazaar data collection
Information collected by Moonshine (Lookout)

The C2 commands supported by the malware are:

  • Call recording
  • Contact collection
  • Retrieve files from a location specified by the C2
  • Collect device location data
  • Exfiltrate SMS messages
  • Camera capture
  • Microphone recording
  • Establish SOCKS proxy
  • Collect WeChat data

Lookout has found evidence that the authors of the new Moonshine version are Chinese, as both code comments and server-side API documentation are written in simplified Chinese.

“While Lookout researchers could not connect the malware client or infrastructure to a specific technology company, the malware client is a well-built and full-featured surveillance tool that would have likely required substantial resources.”

Lookout.

This report indicates that surveillance of Chinese minorities continues unabated despite the outcry from international human rights protection organizations.

Trust this source on GoogleAlways see our reviews and tech guides first in search results
Add trusted source
Tags:#android#apps#BadBazaar#cyberspies#malware#security#virus#vulnerability
Recommended Deals
1 / 5
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

5.0
529.99
Buy on Amazon
Samsung Galaxy Watch 8

Samsung Galaxy Watch 8

4.9
$289.99$349.99-17%
Buy on Amazon
Google Pixel Watch 4

Google Pixel Watch 4

4.8
396.00$499.99-21%
Buy on Amazon
✨DEAL
Google Pixel 11 Pro

Google Pixel 11 Pro

5.0
1,099.00$1,299.00-15%
Buy on Amazon
✨DEAL!
Samsung Galaxy Watch Ultra (2025)

Samsung Galaxy Watch Ultra (2025)

5.0
$449.99$649.99-31%
Buy on Amazon
* As an Amazon Associate, Droid Tools earns from qualifying purchases. Read our editorial policy
Robert Haba
Robert HabaFounder · Editor-in-Chief
X

Robert Haba is the founder and editor-in-chief of Droid Tools. A lifelong gadget enthusiast with over a decade following the Android ecosystem, he built this publication to cut through the noise and give readers honest, real-world coverage of the tech they actually use.

Advertisement

Comments & Discussions

Join the conversation! We use Disqus to handle comments. Click the button below to load the comment section.

Advertisement

Latest Stories

01

Honor MagicOS 11 to debut with hidden Power Saving Suggestions feature

02

Galaxy Watch 4 and Watch 4 Classic reach end of software support

03

GrapheneOS merges Secure Paste to limit clipboard access

04

Android 17 quietly blocks apps from detecting Developer Mode status

Advertisement
Amazon Deals
5.0
Google Pixel Watch 5 (45mm)

Google Pixel Watch 5 (45mm)

Best Price
529.99
Buy

Top Deals

Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Deal
Pixel Watch 5 vs. Pixel Watch 4: what actually changed

Apple Watch Series 12 vs Pixel Watch 5: how they compare

Deal
Apple Watch Series 12 vs Pixel Watch 5: how they compare

Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon

Deal
Garmin Epix Pro Gen 2 Sapphire Edition drops to under $700 at Amazon
Advertisement
Advertisement
Recommended stories

Continue reading

More from this category →
android 17 developer mode
AppsSep 14, 2026

Android 17 quietly blocks apps from detecting Developer Mode status

Developers have discovered that Android 17 quietly blocks apps from checking whether Developer Options and USB Debugging are turned on, in what's being described as one of the release's hidden changes. Regardless of whether Developer Mode is actually enabled on a device, apps that try to read its status in Android 17 will always get […]

By Cristian Penisoara
samsung ar doogle
AppsSep 10, 2026

Samsung shutting down Quick Measure and AR Doodle apps in 2026

Samsung is retiring two of its longest-running AR apps for Galaxy phones. Galaxy Store listings confirm Quick Measure and AR Doodle will shut down on December 31, 2026, with Samsung saying both tools will return later in improved form. Quick Measure lets a phone's camera estimate real-world distances, while AR Doodle lets users sketch virtual […]

By Luiza Mosneagu
gemini spark
AppsSep 5, 2026

Google Photos integration comes to Gemini Spark for Pro and Ultra users

Gemini Spark, the paid Gemini feature that runs complex, multi-step tasks in the background, is getting a significant addition this week: Google Photos support. The integration, reported by Droid Life, is a major connection for Spark, since it opens the door to Google Photos-related requests that could otherwise take hours to complete manually. As part […]

By Robert Haba
whatsapp lock screen bug
AppsSep 3, 2026

WhatsApp lock-screen bug reportedly exposes photos on some Android phones

A locked Android phone may not be as locked as it seems. A reported WhatsApp behavior suggests that someone with physical access to a locked Android device could potentially reach the phone's photo gallery while answering an incoming WhatsApp video call, though the issue doesn't appear to affect every handset, with results reportedly varying by […]

By Robert Haba
Next in queue

Read the next article

The next story loads as you reach the end. You can also load it using the button.