Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybersecurity firm Volexity believes the group responsible for the attacks is called Storm Cloud while describing the malware as “GIMMICK.”
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During initialization, the sample decodes several pieces of data critical to the malware operation using a rotating addition algorithm... Outside of this data obfuscation, and the use of AES for certain external files, the malware makes little attempt to obfuscate its functionality or presence on the system.
Volexity detected a system running frp, otherwise known as fast reverse proxy, and subsequently detected internal port scanning shortly afterward.
For commands and controls (C2) GIMMICK uses Google Drive, a public cloud hosting service since GIMMICK is a multi-platform malware. | A JSON object with OAuth2 credentials for accessing Google Drive is retrieved from the first decoding loop.
Volexity detected a system running frp, otherwise known as fast reverse proxy, and subsequently detected internal port scanning shortly afterward.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gimmick is a malware family known for providing remote access and control to threat actors, with recent variants specifically targeting macOS users. It is associated with Chinese threat actors and is used for espionage and data exfiltration.
A multi-platform malware implant/backdoor linked to a China-aligned espionage actor. The macOS variant is written mostly in Objective-C, uses Google Drive for C2 via OAuth2 credentials, communicates mainly during working hours to blend with target traffic, can retrieve arbitrary files, execute commands, run as an application or daemon, and includes a self-uninstall capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.