GOSSIPGIRL is a collaborative umbrella designation used for a cluster of highly sophisticated state-linked cyberespionage and cyber-sabotage activity associated with the ecosystems behind Flame, Stuxnet, Duqu, and the Equation Group, with Flowershop/Cheshire Cat also described as part of the collaboration. Rather than a conventional single intrusion set, it is characterized as a supra-group construct encompassing multiple malware development teams and platforms that cooperated on shared operations, tooling, and technical components. Activity associated with GOSSIPGIRL includes advanced espionage, covert access, modular malware development, and support for destructive industrial sabotage. Reported links include Flame and MiniFlame, Duqu and Duqu 2.0 lineage, Stuxnet development, and exploit or code-sharing relationships involving Equation Group tooling. Research cited in connection with this umbrella argues that older Stuxnet components incorporated Flame-related functionality, that Equation-linked tooling used Stuxnet-associated exploits prior to Stuxnet’s public discovery, and that early Stuxnet development also overlapped with Flowershop, suggesting participation by at least four distinct teams. The umbrella has been associated with operations targeting diplomatic venues, entities across the Middle East, and industrial control environments tied to Iran’s nuclear program. Stuxnet, one of the most consequential operations linked to this ecosystem, targeted Siemens industrial control systems and caused physical disruption at Natanz. Flame-related activity is associated with long-term espionage, stealthy modular deployment, and sophisticated propagation techniques, while Duqu-related activity reflects covert intelligence collection and post-exploitation tradecraft. Aliases and related names include GOSSIP GIRL and gossip_girl. Closely associated sub-groups or platforms include Equation Group, Flame, Duqu, Stuxnet, MiniFlame, Gauss, and Flowershop, also known as Cheshire Cat. Available reporting strongly indicates a nation-state context and is widely consistent with a U.S.- and Israel-linked operational ecosystem, but GOSSIPGIRL itself is best understood as the collaborative umbrella rather than a formally attributed standalone actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A collaborative supra threat actor umbrella used by the authors to describe an interrelated cluster behind Stuxnet-era operations, linking multiple platforms and teams including Flame, Duqu, Equation, and a fourth actor tied via Stuxshop/Flowershop.
A collaborative supra threat actor umbrella tying together multiple interrelated espionage actors and malware platforms associated with Stuxnet-era operations, including Flame, Duqu, Equation, and a fourth team linked via Stuxshop/Flowershop.
GOSSIP GIRL is an umbrella activity cluster comprising several advanced threat actor groups, including Equation Group, Flame, Duqu, and Flowershop. This confederation collaborated on the development of Stuxnet and related malware platforms, sharing exploits and development frameworks for cyber-espionage and sabotage operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.