Chainshot
- First seen
- 2019-01-05 00:00:00
- Malware type
- exploit-kit
- Family
- Malware family
- Profile updated
- 2026-07-07 14:52:10
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:cn
Context
Chainshot is an advanced exploit kit known for targeting vulnerabilities in technology and government sectors. It is used primarily for launching sophisticated attacks aimed at exfiltration and espionage.
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2018-5002 (vulnerability)
Detection rules
- MALPEDIA_Win_Chainshot_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Chainshot (report)
- researchcenter.paloaltonetworks.com — Unit42 Slicing Dicing Cve 2018 5002 Payloads New Chainshot Malware (report)
- icebrg.io — Adobe Flash Zero Day Targeted Attack (report)
- Kaspersky — 102771 (report)
- vice.com — Uzbekistan Hacking Operations Uncovered Due To Spectacularly Bad Opsec (report)
- citizenlab.ca — Hooking Candiru Another Mercenary Spyware Vendor Comes Into Focus (report)