GOSSIPGIRL is described in the source content as a collaborative “supra threat actor” umbrella rather than a single threat actor. The content links GOSSIPGIRL to the ecosystem behind Flame, Stuxnet, Duqu, MiniFlame, Gauss, and Equation-related activity, based in part on a leaked CSEC presentation and a signature interpreted as connecting GOSSIPGIRL to Flame ("mod_501_GR_FLAME.pl"). The reporting argues that GOSSIPGIRL represents multi-group, multi-platform cooperation in advanced cyberespionage operations, likely state-linked, but does not attribute it to a specific country with high confidence. According to the content, Flame (also known as Flamer or sKyWIper) is central to this umbrella and was previously analyzed by Crysys Lab, Kaspersky Lab, and Symantec. Flame reportedly used a novel cryptographic attack to impersonate a Windows Update server and spread as if legitimately signed by Microsoft. The content further states that an older version of Stuxnet contained a Flame plugin known as Resource 207, linking Flame to Stuxnet development. Duqu is described as developmentally related to Stuxnet, including shared links involving Stuxnet kernel drivers such as mrxcls.sys and Duqu’s Tilde-D platform. Equation-related activity is also tied into this umbrella through exploit sharing: the Fanny worm reportedly used the Stuxnet LNK exploit CVE-2010-2568 and another privilege-escalation exploit embedded in Resource 207 one to two years before Stuxnet appeared, and researchers noted shared coding practices between Stuxnet and Equation developers. The content highlights claimed discoveries associated with this umbrella: Stuxshop, described as an early Stuxnet command-and-control component, allegedly shares unique code overlaps with Flowershop, also referred to as TeDi SIG17/SIG18 and Cheshire Cat, which the content says was active from 2002 to 2013 and targeted entities across the Middle East. This is presented as evidence of a fourth team involved in early Stuxnet development. The content also describes Duqu 1.5 as an intermediate stage between Duqu 1.0 and Duqu 2.0, reconstructed from an intrusion at a diplomatic talks venue. Its loading chain reportedly used a trojanized floppy kernel driver signed with a stolen certificate, a registry virtual file system, an in-memory orchestrator, an on-disk virtual file system, and plugins for spreading and backdoor access. Finally, the content claims Flame persisted beyond its 2012 cleanup as “Flame 2.0,” with samples reportedly compiled as early as February 2014, including 64-bit Windows builds and AES-256-encrypted second-stage resources, and appearing in VirusTotal by October 2016. Known alias from the provided content: gossipgirl.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.