NEW: Group Profiler — instant APT intel lookup. Try it →

Chimera

G0114 China MITRE ATT&CK →

Overview

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.

Naming & attribution

Chimera is tracked under 1 names across the industry. It uses 59 documented ATT&CK techniques — more than 89% of the 174 groups tracked here. Activity attributed since at least 2018.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1556.001 Domain Controller Authentication — used by 1 of 174 groups
  • T1110.004 Credential Stuffing — used by 2 of 174 groups
  • T1201 Password Policy Discovery — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Ke3chang China — 25 shared techniques (31% overlap)
  • menuPass China — 24 shared techniques (30% overlap)
  • Wizard Spider Russia — 28 shared techniques (29% overlap)
  • APT41 China — 31 shared techniques (28% overlap)
  • Volt Typhoon China — 31 shared techniques (28% overlap)
  • FIN13 — 24 shared techniques (27% overlap)

TTPs — 59 techniques across 12 tactics

Reconnaissance

Resource Development

Persistence

Stealth

Defense Impairment

Credential Access

Command and Control

Tools & malware (6)

PsExec · BloodHound · esentutl · Net · Mimikatz · Cobalt Strike

Reporting (2)