Chaes

S0631

Malware.View on attack.mitre.org

About this malware

Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1027.011
Fileless Storage

Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry.

T1033
System Owner/User Discovery

Chaes has collected the username and UID from the infected machine.

T1036.005
Match Legitimate Resource Name or Location

Chaes has used an unsigned, crafted DLL module named hha.dll that was designed to look like a legitimate 32-bit Windows DLL.

T1048
Exfiltration Over Alternative Protocol

Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol.

T1056
Input Capture

Chaes has a module to perform any API hooking it desires.

T1059.003
Windows Command Shell

Chaes has used cmd to execute tasks on the system.

T1059.005
Visual Basic

Chaes has used VBscript to execute malicious code.

T1059.006
Python

Chaes has used Python scripts for execution and the installation of additional files.

T1059.007
JavaScript

Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process.

T1071.001
Web Protocols

Chaes has used HTTP for C2 communications.

T1082
System Information Discovery

Chaes has collected system information, including the machine name and OS version.

T1105
Ingress Tool Transfer

Chaes can download additional files onto an infected machine.

T1106
Native API

Chaes used the CreateFileW() API function with read permissions to access downloaded payloads.

T1112
Modify Registry

Chaes can modify Registry values to stored information and establish persistence.

T1113
Screen Capture

Chaes can capture screenshots of the infected machine.

View all 28 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Cybereason Chaes Nov 2020 Open source
    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.