GEMCUTTER

Malware type
downloader
Profile updated
2026-07-07 12:36:46

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key. GEMCUTTER checks for the presence of the mutex MicrosoftGMMZJ to ensure only one copy of GEMCUTTER is executing. If the mutex doesn't exist, the malware creates it and continues execution; otherwise, the malware signals the MicrosoftGMMExit event.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Gemcutter_Auto (yara-rule)

Reports & references

  • Mandiant — Rpt Apt30 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Gemcutter (report)

External references