logo

Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS

ID: 0f45a77e-3476-5753-814c-0a3e98176574

STIX ID: report--0f45a77e-3476-5753-814c-0a3e98176574

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2022-03-22

Date Updated: 2026-05-01

...
...

Volexity discovered and dissected a macOS variant of the multi-platform GIMMICK implant used by the Storm Cloud (Chinese espionage) actor: the report details persistence via LaunchAgents, a rotating-addition/AES configuration decoding routine, Google Drive-based command-and-control with an asynchronous GCD-driven workflow, command formats and directories, workday-only beaconing to reduce detection, a recovered SHA1 indicator, and recommended mitigations including Apple XProtect/MRT updates and YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.