Chimera

G0114

Threat group.View on attack.mitre.org

About this group

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.

Techniques used59

Procedure examples59

TechniqueProcedure example
T1003.003
NTDS

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.

T1007
System Service Discovery

Chimera has used net start and net use for system service discovery.

T1012
Query Registry

Chimera has queried Registry keys using reg query \\<host>\HKU\<SID>\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\<host>\HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

T1016
System Network Configuration Discovery

Chimera has used ipconfig, Ping, and tracert to enumerate the IP address and network environment and settings of the local host.

T1018
Remote System Discovery

Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment.

T1021.001
Remote Desktop Protocol

Chimera has used RDP to access targeted systems.

T1021.002
SMB/Windows Admin Shares

Chimera has used Windows admin shares to move laterally.

T1021.006
Windows Remote Management

Chimera has used WinRM for lateral movement.

T1027.010
Command Obfuscation

Chimera has encoded PowerShell commands.

T1033
System Owner/User Discovery

Chimera has used the quser command to show currently logged on users.

T1036.005
Match Legitimate Resource Name or Location

Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.

T1039
Data from Network Shared Drive

Chimera has collected data of interest from network shares.

T1041
Exfiltration Over C2 Channel

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

T1046
Network Service Discovery

Chimera has used the get -b <start ip> -e <end ip> -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.

T1047
Windows Management Instrumentation

Chimera has used WMIC to execute remote commands.

View all 59 procedure examples

Software6

Campaigns0

None recorded.

References2

  1. Cycraft Chimera April 2020 Open source
    Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..
  2. NCC Group Chimera January 2021 Open source
    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.