Chisel (Windows)

First seen
2019-11-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 13:46:24

Context

Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP. It is available across platforms and written in Go. While benign in itself, Chisel has been utilized by multiple threat actors. It was for example observed by SentinelOne during a PYSA ransomware campaign to achieve persistence and used as backdoor. Github: https://github.com/jpillora/chisel

Reports & references

  • sentinelone.com — From The Front Lines Peering Into A Pysa Ransomware Attack (report)
  • arcticwolf.com — Lorenz Ransomware Chiseling In (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Chisel (report)
  • securonix.com — Crontrap Emulated Linux Environments As The Latest Tactic In Malware Staging (report)

External references