POISON CARP is a solo mobile spyware operator known for targeting senior Tibetan groups via tailored social engineering.
Analyst brief
POISON CARP, also tracked as 'Evil Eye', 'Red Dev 16', and 'Earth Empusa', is a threat actor assessed to be a single operator primarily conducting mobile spyware operations. This actor targeted senior members of Tibetan groups between 2018-2019 using tailored social engineering via WhatsApp, posing as NGO workers and journalists. Key TTPs include delivering malicious links that exploit browser vulnerabilities to deploy spyware on iOS and Android devices, alongside using OAuth phishing pages for credential harvesting. Defenders should focus on detecting targeted social engineering attempts via instant messaging platforms, enhancing mobile security monitoring for suspicious links, and watching for anomalous credential usage or OAuth token abuse.
POISON CARP
Evil EyeRed Dev 16Earth Empusa
unknown
Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators posing as NGO workers, journalists, and other fake personas. The links led to code designed to exploit web browser vulnerabilities to install spyware on iOS and Android devices, and in some cases to OAuth phishing pages. This campaign was carried out by what appears to be a single operator that we call POISON CARP.
What primary technical methods does the POISON CARP actor use to compromise targets?+
POISON CARP uses tactics such as delivering malicious links that exploit browser vulnerabilities to deploy spyware on iOS and Android devices, and employing OAuth phishing pages for credential harvesting.