Researchers linked a supply-chain compromise of the Chinese-language chat application MìMì to the China-nexus LuckyMouse/Iron Tiger intrusion set, which distributed trojanized versions for Windows, macOS, and Linux. On macOS, malicious builds starting with version 2.3.0 downloaded and executed the RShell Mach-O backdoor, while related Windows activity used HyperBro and Linux variants also deployed RShell, indicating a coordinated cross-platform operation delivered through the same messaging software.
The campaign reused infrastructure previously associated with LuckyMouse, including overlaps between RShell command-and-control servers and hosting tied to HyperBro, strengthening attribution to the group also tracked as TA428. RShell was described as a C++ implant that communicated over unencrypted BJSON over TCP and supported remote shell and file-management functions, while published indicators included malware hashes, command-and-control servers, and download URLs used to deliver the poisoned application, suggesting a targeted surveillance-focused intrusion via compromised corporate software.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Sekoia published findings with high confidence linking the trojanized macOS MìMì application to the China-nexus LuckyMouse intrusion set. The report also said this was the first time Sekoia had observed LuckyMouse targeting macOS and documented infrastructure overlap with HyperBro operations.
Sekoia determined that the macOS version of the MìMì messaging app had been trojanized since version 2.3.0, which was published on May 26, 2022. The malicious app downloaded and executed the RShell backdoor from 139.180.216.65.
Sekoia noted that LuckyMouse had previously used a compromised messaging application, Able Desktop, in the 2020 StealthyTrident operation documented by ESET. This establishes earlier tradecraft involving trojanized chat software.
Trend Micro reported that the MìMì chat application had been compromised in a campaign targeting Windows, macOS, and Linux users. The operation used HyperBro on Windows and RShell on Linux and macOS, and Trend Micro published associated hashes, C2 infrastructure, and download URLs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourcewelivesecurity.com
Open sourcesecurelist.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.