Proprietary · · 266 days

MiMi installers carried Iron Tiger backdoors

Iron Tiger compromised MiMi's official desktop installers. Windows builds carried HyperBro, while the macOS installer delivered rshell for cross-platform remote access.

MiMi was an Electron chat application distributed from the vendor's own site. Trend Micro reported that attackers replaced or built official desktop packages with malware for Windows, macOS, and Linux, so users received a working chat client and a covert access channel.

Trend Micro found MiMi 2.2.0 and 2.2.1 carried similar additions to electron-main.js, the same post-build JavaScript injection applied to installers on the compromised host server rather than code compiled into the released binaries. The added loader started HyperBro and passed control back to the application.

The macOS path delivered rshell. SEKOIA documented a MiMi 2.3.0 DMG hosted at mimi.mimi3.org on 2022-05-26, with the payload placed under MiMi.app/Contents/Resources/rshell. The implant collected host data and opened a remote shell.

Public reporting attributed the operation to Iron Tiger, also tracked as LuckyMouse or APT27. The campaign was espionage-focused and cross-platform; public sources did not give a reliable victim count.

Notes

  • Trend Micro counted 13 targets: five HyperBro (four in Taiwan, one in the Philippines) and eight rshell (six Taiwan, one Philippines, one both), including a Taiwanese game developer.
  • No cited source documents a trojanised MiMi installer for Linux. MiMi's desktop builds are Windows and macOS; Trend Micro found rshell ELF samples of the same family, which is not the same as a poisoned Linux installer.
  • The host mimi.mimi3.org used throughout this record appears in none of the cited references. Sekoia names the application's site as www.mmimchat[.]com, developed by Xiamen Baiquan Information Technology Co. Ltd.
  • Sekoia could not establish that MiMi is a legitimate application or that its stated developer is a real company, and considered it plausible the app was built or repurposed as a surveillance tool.

Appendix · Affected releases

MiMi windows installer
2.2.0 no sample yet
2.2.1 no sample yet
  • Trend Micro reported that the Windows backdoor code was present in MiMi 2.2.0 and 2.2.1 as an addition to electron-main.js, applied to the hosted installers.
MiMi macos dmg
2.3.0 - 2.3.3 no sample yet
  • SEKOIA observed the MiMi 2.3.0 DMG on the official MiMi site with a 2022-05-26 timestamp.
MiMi linux installer
  • Public sources did not name a specific affected Linux package version.
Payloads and stagesno published version
2.3.0 sha256 8c3be245…c4b796ec download unavailable
2.3.0 sha256 3a9e72b3…970e830a download unavailable

Indicators

  • familyHyperBro
  • familyrshell
  • groupIron Tiger
  • groupLuckyMouse
  • groupAPT27
  • urlhttps://mimi.mimi3.org:443/mimi/mimi-mac.dmg
  • filemimi32.exe
  • filemimi32 2.exe
  • filershell
  • path/Volumes/MiMi 2.3.0/MiMi.app/Contents/Resources/rshell
  • ip139.180.216.65
  • ip103.79.76.88
  • ip103.79.77.178

References

  1. Iron Tiger Compromises Chat Application MiMi, Targets Windows, Mac, and Linux Userstrendmicro.com
  2. Iron Tiger APT is behind a supply chain attack that employed messaging app MiMisecurityaffairs.com
  3. Chinese Hackers Backdoored MiMi Chat App to Target Windows, Linux, macOS Usersthehackernews.com
  4. Chinese Hacker Compromised MiMi Chat App Supply Chaininfosecurity-magazine.com
  5. Chinese Hackers Backdoored MiMi Chat App to Target Windows, Linux, macOS Userscybersecuritynews.com
  6. LuckyMouse uses a backdoored Electron App to target macOSblog.sekoia.io

Source record: proprietary/mimi/meta.yaml