Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS
ID: 0f45a77e-3476-5753-814c-0a3e98176574
STIX ID: report--0f45a77e-3476-5753-814c-0a3e98176574
Feed Name: Volexity Blog
Volexity discovered and dissected a macOS variant of the multi-platform GIMMICK implant used by the Storm Cloud (Chinese espionage) actor: the report details persistence via LaunchAgents, a rotating-addition/AES configuration decoding routine, Google Drive-based command-and-control with an asynchronous GCD-driven workflow, command formats and directories, workday-only beaconing to reduce detection, a recovered SHA1 indicator, and recommended mitigations including Apple XProtect/MRT updates and YARA rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
