High
GIMMICK Malware is a newly discovered malware used by a Chinese espionage threat actor called “Storm Cloud”. GIMMICK is a macOS variant of the malware and reserachers previously discovered a Windows version of the malware as well. The malware is written in Objective C and uses Google Drive (and other public cloud hosting services) for C2 channels. And the malware is configured to communicate with its C2 server on working days to blend in with network traffic in the target environment. The Chinese APT group has been targeting Tibetan organizations and individuals since at least 2018.