Threat actor
BadBazaar
Last fetched
BadBazaar is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
BadBazaar is a mobile spyware tool with variants targeting both Android and iOS devices. It has been linked to Chinese-backed hacking groups, such as APT15. This group is known by various names assigned by different cybersecurity organizations, including Vixen Panda, Ke3chang, Nickel, Playful Taurus, BackdoorDiplomacy, Mirage, GREF, RoyalAPT, Nylon Typhoon, Flea, and Red Vulture. BadBazaar has primarily been used to target Uyghur, Tibetan, and Taiwanese individuals, as well as civil society actors who may oppose Chinese state interests. The spyware is distributed through trojanized apps, including fake versions of popular communication tools like Signal and Telegram, as well as apps tailored to specific communities, such as Uyghur-language Quran apps. Once installed, BadBazaar can collect sensitive data, including call logs, GPS locations, SMS messages, and files. The spyware has also been observed spreading via social media platforms and official app stores. The Chengdu-based contractor, Sichuan Dianke Network Security Technology Co., Ltd. (also known as UPSEC), was linked to the deployment of this malware.
Techniques by tactic
No ATT&CK techniques are recorded for BadBazaar in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to BadBazaar today — this states the absence of a published link, not that BadBazaar has no infrastructure.
References
- https://www.ncsc.gov.uk/news/advisory-badbazaar-moonshine
- https://techcrunch.com/2025/04/09/governments-identify-dozens-of-android-apps-bundled-with-spyware/
- https://www.lookout.com/threat-intelligence/article/badbazaar-surveillanceware-apt15
- https://thecyberexpress.com/global-cybersecurity-agencies-warn-of-spyware/
- https://www.darkreading.com/vulnerabilities-threats/china-continues-harassing-ethnic-groups-spyware
- https://www.reuters.com/technology/cybersecurity/western-intelligence-agencies-warn-spyware-threat-targeting-taiwan-tibetan-2025-04-08/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from BadBazaar into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.