Threat group.View on attack.mitre.org
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
| Technique | Procedure example |
|---|---|
| T1003.003 NTDS |
Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1007 System Service Discovery |
Chimera has used |
| T1012 Query Registry |
Chimera has queried Registry keys using |
| T1016 System Network Configuration Discovery |
Chimera has used ipconfig, Ping, and |
| T1018 Remote System Discovery |
Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment. |
| T1021.001 Remote Desktop Protocol |
Chimera has used RDP to access targeted systems. |
| T1021.002 SMB/Windows Admin Shares |
Chimera has used Windows admin shares to move laterally. |
| T1021.006 Windows Remote Management |
Chimera has used WinRM for lateral movement. |
| T1027.010 Command Obfuscation |
Chimera has encoded PowerShell commands. |
| T1033 System Owner/User Discovery |
Chimera has used the |
| T1036.005 Match Legitimate Resource Name or Location |
Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe. |
| T1039 Data from Network Shared Drive |
Chimera has collected data of interest from network shares. |
| T1041 Exfiltration Over C2 Channel |
Chimera has used Cobalt Strike C2 beacons for data exfiltration. |
| T1046 Network Service Discovery |
Chimera has used the |
| T1047 Windows Management Instrumentation |
Chimera has used WMIC to execute remote commands. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.