ATT&CKSoftwareCHIMNEYSWEEP

CHIMNEYSWEEP

S1149

Malware.View on attack.mitre.org

About this malware

CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target Farsi and Arabic speakers since at least 2012.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1005
Data from Local System

CHIMNEYSWEEP can collect files from compromised hosts.

T1027
Obfuscated Files or Information

CHIMNEYSWEEP can use a custom Base64 alphabet to encode an API decryption key.

T1027.001
Binary Padding

The CHIMNEYSWEEP installer has been padded with null bytes to inflate its size.

T1027.007
Dynamic API Resolution

CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time.

T1027.009
Embedded Payloads

CHIMNEYSWEEP can extract RC4 encrypted embedded payloads for privilege escalation.

T1033
System Owner/User Discovery

CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure.

T1041
Exfiltration Over C2 Channel

CHIMNEYSWEEP can upload collected files to the command-and-control server.

T1053.005
Scheduled Task

CHIMNEYSWEEP can use the Windows `SilentCleanup` scheduled task to enable payload execution.

T1056.001
Keylogging

CHIMNEYSWEEP has the ability to support keylogging.

T1057
Process Discovery

CHIMNEYSWEEP can check if a process name contains “creensaver.”

T1059.001
PowerShell

CHIMNEYSWEEP can invoke the PowerShell command `[Reflection.Assembly]::LoadFile(\"%s\")\n$i=\"\"\n$r=[%s]::%s(\"%s\",[ref] $i)\necho $r,$i\n` to execute secondary payloads.

T1059.005
Visual Basic

CHIMNEYSWEEP has executed a script named cln.vbs on compromised hosts.

T1070.006
Timestomp

CHIMNEYSWEEP can time stomp its executable, previously dating it between 2010 to 2021.

T1071.001
Web Protocols

CHIMNEYSWEEP can send `HTTP GET` requests to  C2.

T1074.001
Local Data Staging

CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value.

View all 31 procedure examples

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant ROADSWEEP August 2022 Open source
    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.