Chaperone
Aliases: Taj Mahal
- First seen
- 2018-09-01 00:00:00
- Malware type
- backdoor, keylogger, screen-capture, spyware, trojan
- Family
- Malware family
- Last IoC activity
- 2026-06-08 09:39:18
- Profile updated
- 2026-07-07 13:03:36
Targeted industries: government-and-public-sector
Context
According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky Lab in the autumn of 2018. This full-blown spying framework consists of two packages named Tokyo and Yokohama. It includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers, and even its own file indexer for the victim’s machine. We discovered up to 80 malicious modules stored in its encrypted Virtual File System, one of the highest numbers of plugins they have ever seen for an APT toolset.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Chaperone_Auto (yara-rule)
Reports & references
- Kaspersky — 91897 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Chaperone (report)
- Kaspersky — 90240 (report)
- github.com — Tajmahal (report)