The Central Tibetan Administration website has been hacked to serve up a Java exploit that drops advanced malware, marking the latest attempt to compromise people hoping for freedom from Chinese control in the province.
The site is one of the Dalai Lama’s official sites. Those who visited xizang-zhiye(dot)org were redirected, via an embedded iframe, to an exploit that leads to the download of the Swisyn Trojan, Kaspersky said.
“At this point in time, it seems that the few systems attacked with this code are located in China and the US, although there could be more,” said Kurt Baumgartner, Kaspersky Lab expert, said in a blog post.
“Backdoors detected with the Swisyn verdict are frequently a part of APT [advanced persistent threat] related toolchains, and this one most certainly is.”
The attacker has been targeting Tibetans since at least 2011, Baumgartner said, often using watering hole attacks, where sites the hacker believes his targets will visit are compromised to serve malware.
Apple machines have also been targeted, whilst spear phishing has also been in use.
Tibetans see plenty of attempts to breach their systems every day, with spear phishing a constant threat. China is often suspected of sponsoring the attacks, just as it was when Android malware appeared in April, posing as a legitimate communications app called Kakao Talk.
China is also suspected of attacks on other activists it considers a threat. Last month, TechWeekEurope revealed attempts on Falun Gong activists with zero-day malware.
China has consistently denied it sponsors any kind of hacking.
What do you know about Internet security? Find out with our quiz!
CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation
Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…
Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…
Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector
Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…
Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…