Malware.View on attack.mitre.org
Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.
| Technique | Procedure example |
|---|---|
| T1027.011 Fileless Storage |
Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry. |
| T1033 System Owner/User Discovery |
Chaes has collected the username and UID from the infected machine. |
| T1036.005 Match Legitimate Resource Name or Location |
Chaes has used an unsigned, crafted DLL module named |
| T1048 Exfiltration Over Alternative Protocol |
Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol. |
| T1056 Input Capture |
Chaes has a module to perform any API hooking it desires. |
| T1059.003 Windows Command Shell |
|
| T1059.005 Visual Basic |
Chaes has used VBscript to execute malicious code. |
| T1059.006 Python |
Chaes has used Python scripts for execution and the installation of additional files. |
| T1059.007 JavaScript |
Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process. |
| T1071.001 Web Protocols |
Chaes has used HTTP for C2 communications. |
| T1082 System Information Discovery |
Chaes has collected system information, including the machine name and OS version. |
| T1105 Ingress Tool Transfer |
Chaes can download additional files onto an infected machine. |
| T1106 Native API |
Chaes used the |
| T1112 Modify Registry |
Chaes can modify Registry values to stored information and establish persistence. |
| T1113 Screen Capture |
Chaes can capture screenshots of the infected machine. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.