Proprietary · · 266 days
MiMi installers carried Iron Tiger backdoors
Iron Tiger compromised MiMi's official desktop installers. Windows builds carried HyperBro, while macOS and Linux installers delivered rshell for cross-platform remote access.
MiMi was an Electron chat application distributed from the vendor's own site. Trend Micro reported that attackers replaced or built official desktop packages with malware for Windows, macOS, and Linux, so users received a working chat client and a covert access channel.
The Windows compromise was closest to the build. Trend Micro found backdoor code inserted before the main MiMi window was created, then compiled into MiMi 2.2.0 and 2.2.1. The added loader started HyperBro and passed control back to the application.
The macOS and Linux path delivered rshell. SEKOIA documented a MiMi 2.3.0 DMG hosted at mimi.mimi3.org on 2022-05-26, with the payload placed under MiMi.app/Contents/Resources/rshell. The implant collected host data and opened a remote shell.
Public reporting attributed the operation to Iron Tiger, also tracked as LuckyMouse or APT27. The campaign was espionage-focused and cross-platform; public sources did not give a reliable victim count.
Appendix · Affected releases
- Trend Micro reported that the Windows backdoor code was present in MiMi 2.2.0 and 2.2.1 before compilation.
- SEKOIA observed the MiMi 2.3.0 DMG on the official MiMi site with a 2022-05-26 timestamp.
- Public sources did not name a specific affected Linux package version.
Indicators
- familyHyperBro
- familyrshell
- groupIron Tiger
- groupLuckyMouse
- groupAPT27
- urlhttps://mimi.mimi3.org:443/mimi/mimi-mac.dmg
- filemimi32.exe
- filemimi32 2.exe
- filershell
- path/Volumes/MiMi 2.3.0/MiMi.app/Contents/Resources/rshell
- ip139.180.216.65
- ip103.79.76.88
- ip103.79.77.178
References
- Iron Tiger Compromises Chat Application MiMi, Targets Windows, Mac, and Linux Userstrendmicro.com
- Iron Tiger APT is behind a supply chain attack that employed messaging app MiMisecurityaffairs.com
- Chinese Hackers Backdoored MiMi Chat App to Target Windows, Linux, macOS Usersthehackernews.com
- Chinese Hacker Compromised MiMi Chat App Supply Chaininfosecurity-magazine.com
- Chinese Hackers Backdoored MiMi Chat App to Target Windows, Linux, macOS Userscybersecuritynews.com
- LuckyMouse uses a backdoored Electron App to target macOSblog.sekoia.io
Source record: proprietary/mimi/meta.yaml