CHIMNEYSWEEP

MITRE ATT&CK: S1149 View on attack.mitre.org

Aliases: CHIMNEYSWEEP

First seen
2012-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:29:38

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:ir country_code:sa

Context

CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target Farsi and Arabic speakers since at least 2012.

Detection coverage

  • 721 Sigma rules

Malware & tools used

  • Local Data Staging (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • CMSTP (attack-pattern)
  • Visual Basic (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Native API (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Binary Padding (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Data from Local System (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • PowerShell (attack-pattern)
  • Non-Standard Encoding (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Dynamic API Resolution (attack-pattern)

Used by threat actors

  • HomeLand Justice (campaign)

Reports & references

  • cloud.google.com — Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against (report)
  • MITRE ATT&CK — S1149 (report)

External references