The MiMi Chat App Supply Chain Attack
Updated 5 Oct 2026 · Incident date 26 May 2022 · vendor binary
MiMi chat 2.3.0 for macOS (Windows builds trojanized from mid-2021)mimi.app/Contents/Resources/app/electron-main.jsTrojanized builds of the MiMi chat app (MìMì, 秘秘) installed backdoors on Windows and macOS. The macOS builds 2.3.0 and later were modified from 26 May 2022. Trend Micro lists the Windows builds 2.2.0 and 2.2.1 as compromised in November 2021.
Trend Micro and Sekoia link the activity to Iron Tiger, also called LuckyMouse. The victims they found were in Taiwan and the Philippines.
What happened
Attackers changed the MiMi installers on the developer's download servers so that they carried backdoor code. Trend Micro downloaded a malicious macOS installer from the legitimate servers in June 2022.
MiMi is an Electron app. The attackers added a block of packed JavaScript to electron-main.js inside the app. Sekoia gives the path mimi.app/Contents/Resources/app/electron-main.js. The packer is the Dean Edwards packer, which starts with eval(function(p,a,c,k,e,d).
On macOS, the script downloads a backdoor named rshell. On Windows, the modified script downloads an executable, a DLL, and a binary file to a temporary folder. The DLL side-loads into a legitimate signed program and runs the HyperBro backdoor, according to Trend Micro.
Trend Micro reports that the attackers changed new releases fast. They modified one macOS release within 1.5 hours of its release. Older releases took about a day. Both the clean and the bad installers were unsigned. Users already click through the macOS unverified developer warning for this app, so the warning gave no signal.
Trend Micro found ten targets in Taiwan and two in the Philippines. It identified one victim, a Taiwanese gaming development company.
Affected versions
The two vendors list slightly different macOS ranges. Check every macOS build from 2.3.0 up.
- macOS: 2.3.0 to 2.3.2 (Trend Micro) or 2.3.0 to 2.3.3 (Sekoia). First change on 26 May 2022.
- Windows: 2.2.0 and 2.2.1. Trend Micro dates the compromised build to 23 November 2021.
- Clean: Trend Micro lists 2.2.10 (6 May 2022) as clean.
- The Android and iOS apps are not affected.
Sekoia gives these SHA-256 hashes for the bad macOS disk images:
- 2.3.0:
f6e0e5c9b9d43e008805644d937770b399f859cbba475ad837805d9adec13a2c - 2.3.1:
4742c1987fdd968d7f094dc5a3ea3e9b5340b47e5a61846ac6ac7ae03fc7288f - 2.3.2:
64e771c894616100202e83f3574f8accc8453138af6709367c99157e33bb613a - 2.3.3:
466981b6aa38ae35a2c0e21a2066b4e803cc0bf76409eeb605892604c20ccf3a
Indicators of compromise
The sources list network addresses, domains, hashes, and a network signature.
- Download server for rshell:
139.180.216.65 - rshell command servers:
103.79.76.88and103.79.77.178(Sekoia), andcenter.veryssl.org(Trend Micro) - Linux rshell server:
45.142.214.193 - Earlier HyperBro server:
138.124.180.108 - Domain seen in victim requests:
trust.veryssl.org - rshell SHA-256:
8c3be245cbbe9206a5d146017c14b8f965ab7045268033d70811d5bcc4b796ecand3a9e72b3810b320fa6826a1273732fee7a8e2b2e5c0fd95b8c36bbab970e830a - Windows DLL:
dlpprem32.dll, signed with a revoked Cheetah Mobile Inc. certificate - Guid file written by rshell:
/tmp/guid - Keepalive packets every 40 seconds over unencrypted TCP. Sekoia publishes a Suricata rule for the 25-byte beacon.
Sekoia saw no persistence in rshell. A restart can remove the process but does not remove the exposure.
How to check
Check for the guid file and the network indicators first. Then hash the installer you used.
ls -l /tmp/guid; shasum -a 256 ~/Downloads/*.dmg | grep -iE 'f6e0e5c9|4742c198|64e771c8|46698132'
Search firewall and DNS logs for 139.180.216.65, 103.79.76.88, 103.79.77.178, and veryssl.org. Check the app for the packer string.
grep -l 'eval(function(p,a,c,k,e,d)' /Applications/mimi.app/Contents/Resources/app/electron-main.js
A match means the file holds packed code. A clean build does not need to contain it.
What to do now
- Remove MiMi from every machine that ran an affected build.
- Block the IP addresses and domains above at the firewall.
- Treat the host as compromised. rshell gives the attacker a shell and file access.
- Rotate credentials that the machine held.
- Reinstall from a build that you checked against a known-good copy.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 86 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED mimi.app/Contents/Resources/app/electron-main.js It now downloads from the internet, runs other programs and restarts itself after a reboot. It did not before.
Frequently asked questions
Which MiMi chat versions were compromised?
Trend Micro lists macOS 2.3.0 to 2.3.2 and Windows 2.2.0 and 2.2.1. Sekoia also lists macOS 2.3.3. The mobile apps are not affected.
What did the MiMi backdoor do?
On macOS it downloaded rshell, a backdoor that runs shell commands and handles files. On Windows it ran the HyperBro backdoor.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.