GOSSIPGIRL is a cryptonym used to describe a collaborative umbrella of highly sophisticated state-linked cyber operations rather than a single, discrete intrusion set. It has been associated with the ecosystem surrounding Flame, Stuxnet, Duqu, and the Equation Group, and is best understood as a supra-actor construct encompassing multiple development teams, malware platforms, and operational components that appear to have cooperated on shared objectives, tooling, or technical capabilities. This umbrella has been linked to some of the most advanced cyberespionage and cyber-sabotage activity publicly documented, particularly operations targeting the Middle East and strategic government, diplomatic, and industrial environments. Activity associated with this ecosystem includes espionage, long-term clandestine access, modular malware development, exploit sharing, and cyber-physical sabotage. Stuxnet is widely assessed as a nation-state operation tied to U.S. and Israeli interests, and the broader GOSSIPGIRL construct is likewise associated with elite state-sponsored capabilities. Platforms and sub-components associated with GOSSIPGIRL include Flame (also known as Flamer or sKyWIper), MiniFlame, Gauss, Duqu, Duqu 2.0, an intermediate Duqu 1.5 stage, Stuxnet, and the Equation Group’s related tooling. Reporting has also proposed links to Flowershop, also known as Cheshire Cat, as a distinct collaborating platform or team. In this framing, Equation, Flame, Duqu, and Flowershop represent cooperating elements within a broader operational umbrella rather than interchangeable names for the same actor. Tradecraft attributed to this umbrella includes modular malware architectures, staged loading chains, in-memory orchestration, virtual file systems, signed driver abuse, stealth and anti-analysis measures, exploit reuse across platforms, and highly selective targeting. Associated malware families have demonstrated advanced persistence, covert command-and-control design, lateral movement, removable-media propagation, and the ability to bridge espionage and sabotage missions. The ecosystem is notable for cross-platform code overlap and developmental relationships among ostensibly separate malware families, suggesting shared engineering resources or tightly coordinated collaboration. GOSSIPGIRL is therefore best characterized as a cooperative nation-state cyber umbrella centered on the operators and developers behind Flame-, Duqu-, Stuxnet-, and Equation-related activity, with possible participation by Flowershop/Cheshire Cat. The term is useful for describing a multi-team structure behind landmark strategic cyber operations, especially where malware lineage, exploit sharing, and operational coordination indicate a common higher-level program rather than a single threat group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A collaborative supra threat actor umbrella used by the authors to describe an interrelated cluster behind Stuxnet-era operations, linking multiple platforms and teams including Flame, Duqu, Equation, and a fourth actor tied via Stuxshop/Flowershop.
A collaborative supra threat actor umbrella tying together multiple interrelated espionage actors and malware platforms associated with Stuxnet-era operations, including Flame, Duqu, Equation, and a fourth team linked via Stuxshop/Flowershop.
GOSSIP GIRL is an umbrella activity cluster comprising several advanced threat actor groups, including Equation Group, Flame, Duqu, and Flowershop. This confederation collaborated on the development of Stuxnet and related malware platforms, sharing exploits and development frameworks for cyber-espionage and sabotage operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.