/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Facebook says it has disrupted a network of China-based hackers using its platform to target the Uyghur community abroad and draw them to malicious websites

Facebook on Wednesday announced new actions to disrupt a network of China-based hackers leveraging the platform to compromise targets in the Uyghur community.

TechCrunch Taylor Hatmaker

Context & Ripple Effects

The reported network follows earlier reporting that malicious sites compromising iPhones had been designed to target Uyghur Muslims in China, making Facebook's action part of a continuing pattern of digital targeting tied to the community. The key change is that Facebook is treating use of its platform to steer people toward those sites as an abuse vector to disrupt, not merely an off-platform security issue.

Facebook had also pursued account-compromise and deceptive-ad operators through a lawsuit over compromised accounts and deceptive ads, while later disruptions of Iranian and Russia- and Belarus-linked activity show a broader pattern of platform-led action against state-linked campaigns.

First-order effects

  • Facebook's disruption removes or constrains a China-based network's ability to use the platform to identify and direct Uyghur targets abroad toward malicious websites.
  • Uyghur users targeted by the network face a reduced immediate exposure through Facebook, while the operators lose a distribution channel central to the reported campaign.

Second-order effects

  • The action makes Facebook's detection and enforcement systems a more consequential point of failure for operators that combine social-platform targeting with off-platform malicious infrastructure.
  • Other platforms used to reach Uyghur communities face sharper pressure to detect the same handoff from social contact to malicious website, particularly given the earlier reporting on Uyghur-targeted iPhone hacking sites.

Third-order effects

  • If such interventions become routine, platform security policy will increasingly cover the full attack path—from social targeting to external malicious destinations—rather than focusing only on harmful content hosted on the service.
  • The recurring attribution of campaigns to China, Iran, and Russia- and Belarus-linked actors may make major platforms more central actors in countering cross-border digital targeting, alongside their role as communications services.

The trend: Social platforms are becoming enforcement points against state-linked cyber campaigns that use online relationships to funnel targets toward external compromise infrastructure.

Discussion

  • @ericgeller Eric Geller on x
    Breaking: Facebook announces that it deleted accounts used by a Chinese govt hacking group to infect expat Uyghur activists and journalists with mobile malware. It also blocked the group's phishing sites and notified targets. https://about.fb.com/... https://twitter.com/...
  • @stephenmcdonell Stephen McDonell on x
    Facebook “said it traced the malware used by the hackers — known as Earth Empusa or Evil Eye — to two companies in #China. Facebook said it was not able to determine whether the Chinese government was involved”. #Xinjiang https://www.cbc.ca/...
  • @campuscodi Catalin Cimpanu on x
    The campaign was attributed to the Evil Eye APT, the one discovered by Google in 2019: https://googleprojectzero.blogspot.com/ ... Later detailed here by Volexity: https://www.volexity.com/... and Trend Micro (as Earth Empusa): https://www.trendmicro.com/...
  • @selectedwisdom Clint Watts on x
    Oh man, some bad stuff here regarding China hacking https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Also the second time the Facebook security team doxes APT contractors after the APT32 dox last December.
  • @levitt_matt Matthew Levitt on x
    Facebook removes cyber-espionage op on its platform that originated in China and mostly targeted Uyghur activists & journalists abroad https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Facebook says it also managed to track down some of the group's Android-specific malware to two Chinese software companies. This is line with recent reporting about Chinese APTs, which often rely on third-party contractors for their offensive tooling https://about.fb.com/... http…
  • @campuscodi Catalin Cimpanu on x
    Facebook's report today also comes one day after the US and allies imposed sanctions on China for its treatment of the Uyghur population. Would have been something if Facebook did this earlier, without some kind of informal backing via the State Department
  • @guyro Guy Rosen on x
    Important work here 👇 https://twitter.com/...
  • @joyce_karam Joyce Karam on x
    Today, Facebook Removed a #China Cyber-Espionage op that targeted around 500 Uyghur activists worldwide. They utilized apps and posing as journalists to hack devices. Targets were in Turkey, US, Syria, Kazakhstan, Australia, Canada & other countries: https://techcrunch.com/...
  • @lilyhnewman Lily Hay Newman on x
    Facebook is getting more public about its threat intelligence work including new findings about Chinese hackers' relentless digital assaults on Uyghurs worldwide. Interesting to see how the company can investigate even though it doesn't operate in China https://www.wired.com/...
  • @nickdemocracy @nickdemocracy on x
    Members of Canada's Uyghur community have been targeted by a sophisticated cyber espionage campaign that has been trying to infect devices with malware to permit surveillance, Facebook said today. https://www.cbc.ca/...
  • @ylecun Yann LeCun on x
    Turns out Facebook has a counter-cyber-espionage division. https://twitter.com/...
  • @w7voa Steve Herman on x
    A #China-linked cyber-espionage group used fake identities on @Facebook to try to trick targets into clicking links to malware-laden websites, according to the social media platform. https://twitter.com/...
  • @korischake Kori Schake on x
    Good work. https://twitter.com/...
  • @stephenmcdonell Stephen McDonell on x
    Thread from Facebook security re hacks emanating from #China targeting Uighur groups: “they created look-alike websites posing as news entities popular with the Uyghur and Turkish communities to deliver malware and take control of targets' devices”. #Xinjiang https://twitter.com/…
  • @erinotoole Erin O'Toole on x
    This is disturbing news. Canadians are being targeted by the Chinese regime on our soil. It's time for the government to take action, protect Canadians, and stand up to the Chinese regime. We can't afford the Liberals' naïve approach to China. https://www.cbc.ca/...
  • @ngleicher Nathaniel Gleicher on x
    5/ (2) to share our findings with the defender community so we can collectively raise our defenses. Our own investigation built on work by others and we look forward to more research based on these IOCs.
  • @ngleicher Nathaniel Gleicher on x
    4/ We're announcing our enforcement publicly and sharing threat indicators broadly for three reasons: (1) to raise awareness among potential target communities so they can take steps to protect themselves;
  • @ngleicher Nathaniel Gleicher on x
    2/ This group operated primarily off-platform: they created look-alike websites posing as news entities popular with the Uyghur and Turkish communities to deliver malware and take control of targets' devices.
  • @ngleicher Nathaniel Gleicher on x
    3/ On Facebook they used fake identities to try to trick their targets into clicking links to their malware-laden websites. Today we removed their remaining fake accounts & blocked their malicious links from being shared on our platform.
  • @andymstone Andy Stone on x
    Facebook threat intelligence analysts and security experts strike again, this time against a group of hackers from China that were targeting Uyghur activists, dissidents and journalists living abroad. https://twitter.com/...
  • @ngleicher Nathaniel Gleicher on x
    1/ Today we removed a cyber-espionage op that originated from China. It targeted predominantly Uyghur activists, journalists & dissidents living abroad in Turkey, Kazakhstan, US, Syria, Australia, Canada & other countries. https://about.fb.com/...
  • @persily Nate Persily on x
    This is a pretty impressive and scary takedown announcement from Facebook's head of security. https://twitter.com/...