ChChes

S0144

Malware.View on attack.mitre.org

About this malware

ChChes is a Trojan that appears to be used exclusively by menuPass. It was used to target Japanese organizations in 2016. Its lack of persistence methods suggests it may be intended as a first-stage tool.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe).

T1057
Process Discovery

ChChes collects its process identifier (PID) on the victim.

T1071.001
Web Protocols

ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header.

T1082
System Information Discovery

ChChes collects the victim hostname, window resolution, and Microsoft Windows version.

T1083
File and Directory Discovery

ChChes collects the victim's %TEMP% directory path and version of Internet Explorer.

T1105
Ingress Tool Transfer

ChChes is capable of downloading files, including additional modules.

T1132.001
Standard Encoding

ChChes can encode C2 data with a custom technique that utilizes Base64.

T1547.001
Registry Run Keys / Startup Folder

ChChes establishes persistence by adding a Registry Run key.

T1553.002
Code Signing

ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked.

T1555.003
Credentials from Web Browsers

ChChes steals credentials stored inside Internet Explorer.

T1573.001
Symmetric Cryptography

ChChes can encrypt C2 traffic with AES or RC4.

T1685
Disable or Modify Tools

ChChes can alter the victim's proxy configuration.

Groups that use it1

Campaigns0

None recorded.

References3

  1. JPCERT ChChes Feb 2017 Open source
    Nakamura, Y.. (2017, February 17). ChChes - Malware that Communicates with C&C Servers Using Cookie Headers. Retrieved November 17, 2024.
  2. PWC Cloud Hopper Technical Annex April 2017 Open source
    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.
  3. Palo Alto menuPass Feb 2017 Open source
    Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.