Storm Cloud is a Chinese espionage threat actor associated with targeted intrusions against organizations and individuals across Asia, with especially well-documented activity against Tibetan communities and organizations since at least 2018. The actor has conducted strategic web-compromise operations in which compromised Tibetan websites selectively served malicious content to intended victims after profiling them, then used social-engineering lures such as fake software update prompts to deliver malware rather than relying on browser exploits. Storm Cloud has been linked to multiple malware families and multi-platform tooling. Its operations have included delivery of downloaders and backdoors such as PLUGDAT, STITCH, GOSLU, BRAINDAMAGE, and the GIMMICK malware family. GIMMICK is a multi-platform implant family observed on Windows and macOS, with command-and-control implemented through public cloud services including Google Drive. The macOS variant is designed to blend into victim environments through customized naming and persistence, and supports reconnaissance, file upload and download, shell command execution, timing changes, and self-uninstallation. Storm Cloud activity has also included use of reverse proxies, internal port scanning, and post-compromise deployment of Linux tooling on servers. Related activity has additionally suggested Android targeting through SpyNote-based applications. The actor demonstrates a combination of reconnaissance, selective victim validation, social-engineering-based initial access, persistence, file theft, command execution, and defense evasion. Its tradecraft emphasizes stealth and targeting discipline, including limiting malware communications to working hours or workdays and tailoring artifacts to the victim environment. The dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
56 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese espionage threat actor linked to the GIMMICK malware family, including a newly identified macOS implant, targeting organizations across Asia.
Named follow-on intrusion set/toolkit associated with the same Moonlight Maze operators after public exposure in 1999; suggested as a possible bridge for proving links between Moonlight Maze and Turla.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.