POISON CARP

Aliases: Evil Eye, Red Dev 16, Earth Empusa

First seen
2018-11-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:58:35

Targeted industries: education-and-nonprofits government-and-public-sector

Targeted regions: country_code:cn country_code:in country_code:np country_code:bt

Context

Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators posing as NGO workers, journalists, and other fake personas. The links led to code designed to exploit web browser vulnerabilities to install spyware on iOS and Android devices, and in some cases to OAuth phishing pages. This campaign was carried out by what appears to be a single operator that we call POISON CARP.

Reports & references

  • citizenlab.ca — Poison Carp Tibetan Groups Targeted With 1 Click Mobile Exploits (report)
  • volexity.com — Digital Crackdown Large Scale Surveillance And Exploitation Of Uyghurs (report)
  • Trend Micro — New Android Spyware Actionspy Revealed Via Phishing Attacks From Earth Empusa (report)

External references