In June 2025, cyber attackers linked to China ramped up espionage campaigns against the Tibetan community, especially around the Dalai Lama’s 90th birthday. Disguising malware as chat apps and prayer tools, the attackers tricked users into downloading trojanized software from fake websites designed to look legitimate. These malicious tools secretly installed malware like Ghost RAT and PhantomNet, giving the attackers control over victims’ devices. The campaigns dubbed Operation GhostChat and Operation PhantomPrayers used clever social engineering, fake GUIs, and tailored malware to gather sensitive information and maintain long-term surveillance, highlighting a calculated attempt to exploit trust and community sentiment for political spying.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox