ATT&CKReferencesCybereason Chaes Nov 2020

Cybereason Chaes Nov 2020

Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
MalwareChaes

Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry.

T1033
System Owner/User Discovery
MalwareChaes

Chaes has collected the username and UID from the infected machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareChaes

Chaes has used an unsigned, crafted DLL module named hha.dll that was designed to look like a legitimate 32-bit Windows DLL.

T1048
Exfiltration Over Alternative Protocol
MalwareChaes

Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol.

T1056
Input Capture
MalwareChaes

Chaes has a module to perform any API hooking it desires.

T1059.003
Windows Command Shell
MalwareChaes

Chaes has used cmd to execute tasks on the system.

T1059.005
Visual Basic
MalwareChaes

Chaes has used VBscript to execute malicious code.

T1059.006
Python
MalwareChaes

Chaes has used Python scripts for execution and the installation of additional files.

T1059.007
JavaScript
MalwareChaes

Chaes has used JavaScript and Node.Js information stealer script that exfiltrates data using the node process.

T1071.001
Web Protocols
MalwareChaes

Chaes has used HTTP for C2 communications.

T1082
System Information Discovery
MalwareChaes

Chaes has collected system information, including the machine name and OS version.

T1105
Ingress Tool Transfer
MalwareChaes

Chaes can download additional files onto an infected machine.

T1106
Native API
MalwareChaes

Chaes used the CreateFileW() API function with read permissions to access downloaded payloads.

T1112
Modify Registry
MalwareChaes

Chaes can modify Registry values to stored information and establish persistence.

T1113
Screen Capture
MalwareChaes

Chaes can capture screenshots of the infected machine.

T1132.001
Standard Encoding
MalwareChaes

Chaes has used Base64 to encode C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareChaes

Chaes has decrypted an AES encrypted binary file to trigger the download of other files.

T1185
Browser Session Hijacking
MalwareChaes

Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts.

T1204.002
Malicious File
MalwareChaes

Chaes requires the user to click on the malicious Word document to execute the next part of the attack.

T1218.004
InstallUtil
MalwareChaes

Chaes has used Installutill to download content.

T1218.007
Msiexec
MalwareChaes

Chaes has used .MSI files as an initial way to start the infection chain.

T1221
Template Injection
MalwareChaes

Chaes changed the template target of the settings.xml file embedded in the Word document and populated that field with the downloaded URL of the next payload.

T1539
Steal Web Session Cookie
MalwareChaes

Chaes has used a script that extracts the web session cookie and sends it to the C2 server.

T1547.001
Registry Run Keys / Startup Folder
MalwareChaes

Chaes has added persistence via the Registry key software\microsoft\windows\currentversion\run\microsoft windows html help.

T1555.003
Credentials from Web Browsers
MalwareChaes

Chaes can steal login credentials and stored financial information from the browser.

T1566.001
Spearphishing Attachment
MalwareChaes

Chaes has been delivered by sending victims a phishing email containing a malicious .docx file.

T1573
Encrypted Channel
MalwareChaes

Chaes has used encryption for its C2 channel.

T1574.001
DLL
MalwareChaes

Chaes has used search order hijacking to load a malicious DLL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.