Volexity linked a late-2021 intrusion against an organization in Asia to Storm Cloud, a China-aligned espionage actor, after recovering a previously undocumented macOS variant of the GIMMICK malware family from a compromised MacBook Pro running macOS 11.6 Big Sur. The implant, written primarily in Objective-C, expands a malware set already seen on Windows in .NET and Delphi, indicating a broader multi-platform toolkit aimed at organizations across the region.
The macOS backdoor was built to evade notice by using customized filenames, persistence mechanisms, and communications limited to workdays and working hours, while relying on Google Drive for command-and-control. Volexity said the malware supports reconnaissance, file retrieval and transfer, shell command execution, timing changes, and self-uninstallation; Apple later worked with the firm and pushed XProtect and MRT signatures on March 17, 2022 to detect, block, and remove GIMMICK from affected macOS systems.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Apple collaborated with Volexity and on March 17, 2022 pushed new XProtect and MRT signatures to block and remove GIMMICK from macOS systems. Volexity said this provided protection for Apple users against the malware.
During forensic and memory analysis of the compromised MacBook Pro, Volexity recovered and identified a previously unreported macOS variant of the GIMMICK malware family. The implant was linked to Storm Cloud and assessed as part of a broader multi-platform malware set that also includes Windows variants.
In late 2021, Volexity detected an intrusion in a monitored environment involving a compromised MacBook Pro running macOS 11.6 Big Sur. The activity included unauthorized use of frp/fast reverse proxy and internal port scanning, and Volexity attributed the intrusion to the China-linked espionage actor Storm Cloud.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcevolexity.com
Open sourcedeveloper.apple.com
Open sourcedeveloper.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.