Malware
GEMCUTTER
According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key.
GEMCUTTER is a Windows malware family operated by APT 30.
Background
FireEye notes that GEMCUTTER serves much the same downloader role as BACKBEND, but achieves persistence by writing a Windows registry run key. To guarantee a single running instance, it checks for the mutex MicrosoftGMMZJ; if absent, it creates the mutex and proceeds, and if present, it instead signals the MicrosoftGMMExit event.
Source: Malpedia (Fraunhofer FKIE).