← threatfilter.dev / all groups / Chimera
Chimera
Overview
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
TTPs — 59 techniques across 12 tactics
Reconnaissance
-
T1589.001Credentials
Resource Development
-
T1588.002Tool
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1106Native API -
T1569.002Service Execution
Persistence
-
T1133External Remote Services
Stealth
-
T1027.010Command Obfuscation -
T1036.005Match Legitimate Resource Name or Location -
T1070.004File Deletion -
T1070.006Timestomp -
T1078Valid Accounts -
T1078.002Domain Accounts -
T1574.001DLL
Defense Impairment
-
T1556.001Domain Controller Authentication -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.003NTDS -
T1110.003Password Spraying -
T1110.004Credential Stuffing -
T1111Multi-Factor Authentication Interception
Discovery
-
T1007System Service Discovery -
T1012Query Registry -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1046Network Service Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1069.001Local Groups -
T1083File and Directory Discovery -
T1087.001Local Account -
T1087.002Domain Account -
T1124System Time Discovery -
T1135Network Share Discovery -
T1201Password Policy Discovery -
T1217Browser Information Discovery -
T1482Domain Trust Discovery -
T1680Local Storage Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares -
T1021.006Windows Remote Management -
T1550.002Pass the Hash -
T1570Lateral Tool Transfer
Collection
-
T1039Data from Network Shared Drive -
T1074.001Local Data Staging -
T1074.002Remote Data Staging -
T1114.001Local Email Collection -
T1114.002Remote Email Collection -
T1119Automated Collection -
T1213.002Sharepoint -
T1560.001Archive via Utility
Command and Control
-
T1071.001Web Protocols -
T1071.004DNS -
T1105Ingress Tool Transfer -
T1572Protocol Tunneling
Exfiltration
-
T1041Exfiltration Over C2 Channel -
T1567.002Exfiltration to Cloud Storage
Tools & malware (6)
PsExec · BloodHound · esentutl · Net · Mimikatz · Cobalt Strike