Threat Advisories:

Operation GhostChat and PhantomPrayers Breach Tibetan Trust

Amber | Attack Report
Download PDF

In June 2025, cyber attackers linked to China ramped up espionage campaigns against the Tibetan community, especially around the Dalai Lama’s 90th birthday. Disguising malware as chat apps and prayer tools, the attackers tricked users into downloading trojanized software from fake websites designed to look legitimate. These malicious tools secretly installed malware like Ghost RAT and PhantomNet, giving the attackers control over victims’ devices. The campaigns dubbed Operation GhostChat and Operation PhantomPrayers used clever social engineering, fake GUIs, and tailored malware to gather sensitive information and maintain long-term surveillance, highlighting a calculated attempt to exploit trust and community sentiment for political spying.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs