HomeSecurityStorm Cloud: Custom macOS malware discovered

Storm Cloud: Custom macOS malware discovered

Security researchers have discovered a previously unknown variant of a macOS malware called GIMMICK, which is believed to be a custom tool used by a Chinese espionage agent known as "Storm Cloud."

See also: BitRAT malware: Appears as Windows 10 license activator and infects users

macOS malware

The macOS malware was discovered by researchers at Volexity, who recovered it from the RAM of a MacBook Pro running macOS 11.6 (Big Sur), which had been compromised in a cyberespionage campaign in late 2021.

Exposure of custom malware used by sophisticated threat actors is not common. These groups operate very carefully, leaving a minimal footprint and wiping out malware remnants to keep their tools secret and avoid IoC-based detection.

However, sometimes even the most advanced cybercriminals leave behind malware that can then be analyzed by security researchers, as is the case with GIMMICK.

GIMMICK is a cross-platform malware written in Objective C (macOS) or .NET and Delphi (Windows).

All variants use the same C2 architecture, file paths, behavior patterns, and heavily abuse Google Drive services, so it is tracked as one tool despite the differences in code.

GIMMICK is launched and installed as a binary file named "PLIST", usually emulating a widely used application on the target machine.

The malware then initializes by performing several data decoding steps and finally creates a session on Google Drive, using hard-coded OAuth2 credentials.

See also: ASUS: Cyclops Blink malware targets the company's routers

After preparation, GIMMICK loads three malware components, DriveManager, FileManager, and GCDTimerManager, with the first one responsible for the following actions:

  • Manage Google Drive and proxy sessions.
  • Maintain a local map of the Google Drive directory hierarchy in memory.
  • Manage locks for task synchronization in your Google Drive session.
  • Handling download and upload tasks to and from your Google Drive session.
macOS malware

The UUID of each infected system is used as an identifier for the Google Drive directory that corresponds to it.

The FileManager manages the local directory where C2 information and command jobs are stored, and the GCDTimerManager handles the management of the various GCD objects.

See also: New macOS 12.3 update renders Macs with altered logic boards unusable

Apple has also made new protections available to all supported macOS versions with new signatures for XProtect and MRT, which will be able to block and remove malware starting March 17, 2022. To make sure you have received these signatures, follow the instructions on support page .

To prevent GIMMICK and similar malware from invading your macOS, start by applying the available system updates for device , which will also bring the latest detection signatures.

Next, make sure that XProtect and MRT are enabled and actively running on the system.

Advanced measures include using network traffic monitoring tools and EDR solutions to detect malware on endpoints.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS