Jul 24, 2026 · 7 min read
China Linked Hackers Used Fake Google Alerts on Journalists
Citizen Lab and ICIJ say two China linked hacking crews, tracked as GLITTER CARP and SEQUIN CARP, spent roughly nine months phishing journalists and Uyghur, Tibetan, Hong Kong, and Taiwanese activists using fake Google security alerts and OAuth consent pages built to take over Gmail accounts.
Uyghur Canadian activist Mehmet Tohti got a WhatsApp message in April 2025 from someone claiming to be a well known Uyghur film director, asking for his email address. He didn't hand over his Google password when a link followed. What arrived instead was a fake Google security alert, written in Chinese, warning that his account had just been accessed from an unfamiliar device.
That alert wasn't only bait for a click. According to a joint investigation by Citizen Lab and the International Consortium of Investigative Journalists (ICIJ), published April 27, 2026, the email carried a hidden 1x1 tracking pixel that reported to the attackers the moment Tohti's inbox rendered it, click or no click. Researchers tied it to two operations, codenamed GLITTER CARP and SEQUIN CARP, both attributed with high confidence to actors affiliated with the Chinese government, likely operating as commercial contractors.
Key Takeaways
- Citizen Lab and ICIJ's April 27, 2026 report, "Tall Tales," ties two phishing operations, GLITTER CARP and SEQUIN CARP, to Chinese government contractors who ran more than 100 malicious domains over roughly nine months, according to The Record.
- GLITTER CARP's fake Google security alert emails embedded hidden 1x1 tracking pixels that report an open timestamp and device details the instant a message renders, with no click required.
- SEQUIN CARP skipped credential theft for some targets entirely, walking victims through a real Google OAuth consent screen that hands attackers a Gmail refresh token surviving a password reset.
- Named targets include ICIJ journalist Scilla Alecci, Uyghur activist Mehmet Tohti, Hong Kong activist Carmen Lau, and groups including the World Uyghur Congress and the Uyghur Human Rights Project.
- Both campaigns echo Citizen Lab's 2019 Poison Carp report, which hit the same Tibetan and Uyghur diaspora via WhatsApp personas, but swapped six figure mobile exploit chains for phishing kits and OAuth pages costing a fraction as much.
What Are GLITTER CARP and SEQUIN CARP?
GLITTER CARP and SEQUIN CARP are the names Citizen Lab gave two phishing operations sharing infrastructure and a likely source: freelance contractors working for the Chinese government. GLITTER CARP is the broader, blunter one, running a credential harvesting adversary in the middle (AiTM) kit against Uyghur, Tibetan, Hong Kong, and Taiwanese diaspora groups plus ICIJ staff. SEQUIN CARP is narrower and more patient, focused mainly on ICIJ's Scilla Alecci and other journalists, leaning on invented personas, a whistleblower who fled to Japan, a fake researcher named Hans Witting, over technical polish; sender names even changed between emails from the same address. Citizen Lab frames both as proof of a broader shift toward outsourced, profit driven repression that scales cheaply, according to The Record, which counted nine months and over 100 domains behind it.
How Did the Fake Google Alerts Actually Track Journalists?
The fake alerts tracked recipients through an invisible 1x1 pixel, the same mechanism marketing platforms use to confirm a newsletter was opened, repurposed here to confirm an espionage target's account is alive. When a victim's email client fetched that image while rendering the message, it sent a request to attacker infrastructure carrying an open timestamp and device details, before anyone clicked a link or typed a password. Citizen Lab found the pixels lived on dozens of throwaway hostnames dressed up as harmless content, in some cases Spanish language cocktail recipes, a triage tool for seeing which inboxes are worth a follow up instead of burning a phishing page on a dead account.
How Does the OAuth Trick Steal Gmail Without a Password?
SEQUIN CARP's most effective technique never touches a password. A link to a cloud hosted file with an innocuous name, something like GoogleVerify.html, routes the victim through a real accounts.google.com consent screen requesting the full mail.google.com scope alongside access_type=offline. Approve that once and Google hands the attacker a refresh token with full read, send, and delete access that keeps working after a password change, because it was never a password based login. The victim is talking to Google the entire time, which is what makes it hard to catch: the phishing lives in the permission granted, not a stolen credential. Citizen Lab traced the callback infrastructure to domains including oauth2-signal[.]com.
Who Did China Target?
The named victims span journalism and diaspora activism, plus a Pentagon focused defense reporter among SEQUIN CARP's targets. Confirmed victims include Alecci, Tohti, Hong Kong activist Carmen Lau, who lives in the UK and is wanted by Hong Kong police, and staff at the World Uyghur Congress, the Uyghur Human Rights Project, and TibCERT. Taiwanese outlet Watchout was hit through Line, and a separate UHRP staffer through Signal, the same opening move used against Tohti.
None of this is a new playbook so much as a cheaper version of an old one. Citizen Lab used the same "Carp" naming convention in 2019 for Poison Carp, which hit the Dalai Lama's office with one click mobile exploit chains through the same kind of WhatsApp personas, chains that were expensive and hard to replace once burned. Seven years later, the payload against the same diaspora is a phishing kit and an OAuth screen anyone can rent, matching what Gblock's coverage of the IFJ's global survey of surveillance vendors targeting journalists found industry wide: cheap phishing is replacing six figure exploits.
The raw material for campaigns like this is a list of verified addresses, and those lists keep leaking from the institutions reporters correspond with. South Korea's foreign ministry disclosed in July 2026 that a decade old training server sat compromised for ten months, exposing the email accounts of roughly 6,000 diplomats including hundreds posted abroad.
Why Email Users Should Care
This story isn't only about diaspora activists and reporters. The pixel GLITTER CARP hid in its fake Google alerts is structurally identical to what marketing platforms embed in ordinary newsletters, a transparent 1x1 image that fires the instant your inbox renders it, logging your open time, device, and rough location without a click. State backed hackers didn't invent this trick; they borrowed it from adtech because it already does exactly what espionage needs: quiet, click free confirmation that an inbox is alive.
A pixel confirming an activist's account is worth a follow up attack runs on the same logic as one telling a marketer you opened their promo at 11:47 p.m. Gblock strips those invisible pixels out of Gmail automatically, which won't stop an OAuth consent phish on its own, but it closes the exact open confirmation mechanic this campaign relied on. See Gblock's guide to detecting email tracking pixels in Gmail to spot one yourself.
What Should Journalists and Activists Do Right Now?
The tradecraft here is uneven, SEQUIN CARP's own persona slip ups prove that, but the social engineering doesn't need to be perfect against a busy or frightened target. A few concrete steps reduce exposure:
- Treat any unsolicited WhatsApp, Signal, or Line message asking for your email address as a targeting attempt on its own, and verify identity through a second channel before replying.
- Audit connected apps at myaccount.google.com/permissions and revoke anything unfamiliar. It's the only way to kill an OAuth refresh token, since a password change does nothing to a grant that was never a password login.
- Slow down on any "security alert" email long enough to check the sender domain, and treat any alert asking you to confirm account access as itself the attack until proven otherwise.
- Report suspected state linked phishing to your security team and to groups such as Citizen Lab or the Committee to Protect Journalists, so the pattern gets documented rather than staying isolated in one inbox.
SEQUIN CARP's tracked activity had gone quiet by March 2026, a month before publication, but the economics haven't changed. Contractors this cheap don't retire. They rebrand, rotate domains, and resurface under a new codename the next time a diaspora community becomes inconvenient to Beijing.
Sources: Citizen Lab and ICIJ, The Record, and The Hacker News.