Researchers say China's mobile hacking campaign against the Uighurs was broader and more aggressive than previously known, beginning as far back as 2013
A new report revealed a broad campaign that targeted Muslims in China and their diaspora in other countries, beginning as early as 2013.
Context & Ripple Effects
The 2020 report extends a story that broke in stages through 2019. Researchers had already traced malicious websites used to hack iPhones of Uighurs — with Android and Windows targets in the same infrastructure — and documented how Chinese hackers compromised telecom operators in Turkey, India, Thailand, and Malaysia to track Uighur travelers abroad. By late 2019, researchers described a deliberate shift in state-sponsored hacking tactics toward ethnic minorities.
What is new here is scope and timeline: the campaign now reaches back to 2013 and explicitly covers the diaspora outside China, not just Uighurs inside the country. A later disclosure that the US quietly told Apple a contest-winning Qihoo 360 researcher's iPhone 0-day was used against Uyghurs reinforces that the targeting drew on elite exploit capability, not opportunistic malware.
First-order effects
- Uighurs and Muslim diaspora members in third countries are confirmed targets of a seven-year-plus mobile campaign, making host-country phone security — not just activity inside China — the exposure surface.
- Apple and other mobile platform vendors face renewed scrutiny over how long exploit chains aimed at this population went undetected, following the earlier malicious-website disclosures.
Second-order effects
- Telecom operators in Turkey, India, Thailand, and Malaysia, already named as compromised vantage points, come under pressure from governments and customers to harden networks against state-sponsored intrusions.
- Security researchers and vendors treating minority-targeted espionage as a distinct category gain a stronger case for dedicated tracking, pushing detection budgets toward diaspora-focused threat intelligence.
Third-order effects
- If the pattern holds, transnational repression via mobile exploitation becomes a standing feature of state hacking — diaspora populations treated as legitimate intelligence targets regardless of where they live, forcing platform makers and host governments to treat the problem as geopolitical rather than purely criminal.
- Sustained targeting of one ethnic group since at least 2013 strengthens the case that export controls and platform security policy will increasingly be written around specific state campaigns rather than generic threat categories.
The trend: State-sponsored mobile espionage is converging on diaspora populations as a standing target set, with exploit capability and telecom compromise replacing borders as the limit on surveillance reach.