The MiMi Chat App Supply Chain Attack

Updated 5 Oct 2026 · Incident date 26 May 2022 · vendor binary

PackageMiMi chat 2.3.0 for macOS (Windows builds trojanized from mid-2021)
Filemimi.app/Contents/Resources/app/electron-main.js

Trojanized builds of the MiMi chat app (MìMì, 秘秘) installed backdoors on Windows and macOS. The macOS builds 2.3.0 and later were modified from 26 May 2022. Trend Micro lists the Windows builds 2.2.0 and 2.2.1 as compromised in November 2021.

Trend Micro and Sekoia link the activity to Iron Tiger, also called LuckyMouse. The victims they found were in Taiwan and the Philippines.

What happened

Attackers changed the MiMi installers on the developer's download servers so that they carried backdoor code. Trend Micro downloaded a malicious macOS installer from the legitimate servers in June 2022.

MiMi is an Electron app. The attackers added a block of packed JavaScript to electron-main.js inside the app. Sekoia gives the path mimi.app/Contents/Resources/app/electron-main.js. The packer is the Dean Edwards packer, which starts with eval(function(p,a,c,k,e,d).

On macOS, the script downloads a backdoor named rshell. On Windows, the modified script downloads an executable, a DLL, and a binary file to a temporary folder. The DLL side-loads into a legitimate signed program and runs the HyperBro backdoor, according to Trend Micro.

Trend Micro reports that the attackers changed new releases fast. They modified one macOS release within 1.5 hours of its release. Older releases took about a day. Both the clean and the bad installers were unsigned. Users already click through the macOS unverified developer warning for this app, so the warning gave no signal.

Trend Micro found ten targets in Taiwan and two in the Philippines. It identified one victim, a Taiwanese gaming development company.

Affected versions

The two vendors list slightly different macOS ranges. Check every macOS build from 2.3.0 up.

Sekoia gives these SHA-256 hashes for the bad macOS disk images:

Indicators of compromise

The sources list network addresses, domains, hashes, and a network signature.

Sekoia saw no persistence in rshell. A restart can remove the process but does not remove the exposure.

How to check

Check for the guid file and the network indicators first. Then hash the installer you used.

ls -l /tmp/guid; shasum -a 256 ~/Downloads/*.dmg | grep -iE 'f6e0e5c9|4742c198|64e771c8|46698132'

Search firewall and DNS logs for 139.180.216.65, 103.79.76.88, 103.79.77.178, and veryssl.org. Check the app for the packer string.

grep -l 'eval(function(p,a,c,k,e,d)' /Applications/mimi.app/Contents/Resources/app/electron-main.js

A match means the file holds packed code. A clean build does not need to contain it.

What to do now

  1. Remove MiMi from every machine that ran an affected build.
  2. Block the IP addresses and domains above at the firewall.
  3. Treat the host as compromised. rshell gives the attacker a shell and file access.
  4. Rotate credentials that the machine held.
  5. Reinstall from a build that you checked against a known-good copy.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old MiMi-prev --new MiMi-current
files scanned: 86

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    mimi.app/Contents/Resources/app/electron-main.js
           It now downloads from the internet, runs other programs and restarts itself after a reboot. It did not before.

Frequently asked questions

Which MiMi chat versions were compromised?

Trend Micro lists macOS 2.3.0 to 2.3.2 and Windows 2.2.0 and 2.2.1. Sekoia also lists macOS 2.3.3. The mobile apps are not affected.

What did the MiMi backdoor do?

On macOS it downloaded rshell, a backdoor that runs shell commands and handles files. On Windows it ran the HyperBro backdoor.

Sources

  1. sekoia.com/blog/luckymouse-uses-a-backdoored-electron-app-to-target-macos
  2. trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html
  3. securityweek.com/chinese-cyberspies-use-supply-chain-attack-deliver-windows-macos-malware/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free