Skip to content

Malware

GEMCUTTER

According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key.

GEMCUTTER is a Windows malware family operated by APT 30.

Background

FireEye notes that GEMCUTTER serves much the same downloader role as BACKBEND, but achieves persistence by writing a Windows registry run key. To guarantee a single running instance, it checks for the mutex MicrosoftGMMZJ; if absent, it creates the mutex and proceeds, and if present, it instead signals the MicrosoftGMMExit event.


Source: Malpedia (Fraunhofer FKIE).