Chainshot

First seen
2019-01-05 00:00:00
Malware type
exploit-kit
Family
Malware family
Profile updated
2026-07-07 14:52:10

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:cn

Context

Chainshot is an advanced exploit kit known for targeting vulnerabilities in technology and government sectors. It is used primarily for launching sophisticated attacks aimed at exfiltration and espionage.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2018-5002 (vulnerability)

Detection rules

  • MALPEDIA_Win_Chainshot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Chainshot (report)
  • researchcenter.paloaltonetworks.com — Unit42 Slicing Dicing Cve 2018 5002 Payloads New Chainshot Malware (report)
  • icebrg.io — Adobe Flash Zero Day Targeted Attack (report)
  • Kaspersky — 102771 (report)
  • vice.com — Uzbekistan Hacking Operations Uncovered Due To Spectacularly Bad Opsec (report)
  • citizenlab.ca — Hooking Candiru Another Mercenary Spyware Vendor Comes Into Focus (report)

External references