Facebook says it has disrupted a network of China-based hackers using its platform to target the Uyghur community abroad and draw them to malicious websites
Facebook on Wednesday announced new actions to disrupt a network of China-based hackers leveraging the platform to compromise targets in the Uyghur community.
TechCrunchTaylor Hatmaker
Context & Ripple Effects
The reported network follows earlier reporting that malicious sites compromising iPhones had been designed to target Uyghur Muslims in China, making Facebook's action part of a continuing pattern of digital targeting tied to the community. The key change is that Facebook is treating use of its platform to steer people toward those sites as an abuse vector to disrupt, not merely an off-platform security issue.
Facebook had also pursued account-compromise and deceptive-ad operators through a lawsuit over compromised accounts and deceptive ads, while later disruptions of Iranian and Russia- and Belarus-linked activity show a broader pattern of platform-led action against state-linked campaigns.
First-order effects
Facebook's disruption removes or constrains a China-based network's ability to use the platform to identify and direct Uyghur targets abroad toward malicious websites.
Uyghur users targeted by the network face a reduced immediate exposure through Facebook, while the operators lose a distribution channel central to the reported campaign.
Second-order effects
The action makes Facebook's detection and enforcement systems a more consequential point of failure for operators that combine social-platform targeting with off-platform malicious infrastructure.
Other platforms used to reach Uyghur communities face sharper pressure to detect the same handoff from social contact to malicious website, particularly given the earlier reporting on Uyghur-targeted iPhone hacking sites.
Third-order effects
If such interventions become routine, platform security policy will increasingly cover the full attack path—from social targeting to external malicious destinations—rather than focusing only on harmful content hosted on the service.
The recurring attribution of campaigns to China, Iran, and Russia- and Belarus-linked actors may make major platforms more central actors in countering cross-border digital targeting, alongside their role as communications services.
The trend: Social platforms are becoming enforcement points against state-linked cyber campaigns that use online relationships to funnel targets toward external compromise infrastructure.
Breaking: Facebook announces that it deleted accounts used by a Chinese govt hacking group to infect expat Uyghur activists and journalists with mobile malware. It also blocked the group's phishing sites and notified targets. https://about.fb.com/... https://twitter.com/...
Facebook “said it traced the malware used by the hackers — known as Earth Empusa or Evil Eye — to two companies in #China. Facebook said it was not able to determine whether the Chinese government was involved”. #Xinjiang https://www.cbc.ca/...
The campaign was attributed to the Evil Eye APT, the one discovered by Google in 2019: https://googleprojectzero.blogspot.com/ ... Later detailed here by Volexity: https://www.volexity.com/... and Trend Micro (as Earth Empusa): https://www.trendmicro.com/...
Facebook removes cyber-espionage op on its platform that originated in China and mostly targeted Uyghur activists & journalists abroad https://twitter.com/...
Facebook says it also managed to track down some of the group's Android-specific malware to two Chinese software companies. This is line with recent reporting about Chinese APTs, which often rely on third-party contractors for their offensive tooling https://about.fb.com/... http…
Facebook's report today also comes one day after the US and allies imposed sanctions on China for its treatment of the Uyghur population. Would have been something if Facebook did this earlier, without some kind of informal backing via the State Department
Today, Facebook Removed a #China Cyber-Espionage op that targeted around 500 Uyghur activists worldwide. They utilized apps and posing as journalists to hack devices. Targets were in Turkey, US, Syria, Kazakhstan, Australia, Canada & other countries: https://techcrunch.com/...
Facebook is getting more public about its threat intelligence work including new findings about Chinese hackers' relentless digital assaults on Uyghurs worldwide. Interesting to see how the company can investigate even though it doesn't operate in China https://www.wired.com/...
Members of Canada's Uyghur community have been targeted by a sophisticated cyber espionage campaign that has been trying to infect devices with malware to permit surveillance, Facebook said today. https://www.cbc.ca/...
A #China-linked cyber-espionage group used fake identities on @Facebook to try to trick targets into clicking links to malware-laden websites, according to the social media platform. https://twitter.com/...
Thread from Facebook security re hacks emanating from #China targeting Uighur groups: “they created look-alike websites posing as news entities popular with the Uyghur and Turkish communities to deliver malware and take control of targets' devices”. #Xinjiang https://twitter.com/…
This is disturbing news. Canadians are being targeted by the Chinese regime on our soil. It's time for the government to take action, protect Canadians, and stand up to the Chinese regime. We can't afford the Liberals' naïve approach to China. https://www.cbc.ca/...
5/ (2) to share our findings with the defender community so we can collectively raise our defenses. Our own investigation built on work by others and we look forward to more research based on these IOCs.
4/ We're announcing our enforcement publicly and sharing threat indicators broadly for three reasons: (1) to raise awareness among potential target communities so they can take steps to protect themselves;
2/ This group operated primarily off-platform: they created look-alike websites posing as news entities popular with the Uyghur and Turkish communities to deliver malware and take control of targets' devices.
3/ On Facebook they used fake identities to try to trick their targets into clicking links to their malware-laden websites. Today we removed their remaining fake accounts & blocked their malicious links from being shared on our platform.
Facebook threat intelligence analysts and security experts strike again, this time against a group of hackers from China that were targeting Uyghur activists, dissidents and journalists living abroad. https://twitter.com/...
1/ Today we removed a cyber-espionage op that originated from China. It targeted predominantly Uyghur activists, journalists & dissidents living abroad in Turkey, Kazakhstan, US, Syria, Australia, Canada & other countries. https://about.fb.com/...