GREF

First seen
2017-03-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-15 16:45:04
Profile updated
2026-07-07 12:11:24

Targeted industries: technology-and-telecommunications media-and-entertainment government-and-public-sector

Targeted regions: country_code:cn country_code:tr

Context

GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loaders, and ancillary tools in their targeted attacks. Recently, they have been attributed to two active Android campaigns that distribute the BadBazaar malware through malicious apps on official and alternative app stores. GREF has targeted Android users, particularly Uyghurs and other Turkic ethnic minorities outside of China, using trojanized versions of popular messaging apps like Signal and Telegram.

Reports & references

  • ESET — Badbazaar Espionage Tool Targets Android Users Trojanized Signal Telegram Apps (report)

External references