Chimera
MITRE ATT&CK: G0114 View on attack.mitre.org
Aliases: Chimera
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 15 (10 malicious)
- Last IoC activity
- 2026-09-02 02:41:20
- Profile updated
- 2026-07-07 12:30:37
Targeted industries: technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:tw
Context
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
Recent IoC activity
10 malicious indicators in Maltiverse are attributed to Chimera (G0114). The 10 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | https://github.com/ducat04/ducats-nuker/releases/tag/nuke | 2026-09-01 | 1 |
| file sample | Default-Dark-Mode-1.21.11-2026.4.0.zip | 2026-08-20 | 1 |
| URL | https://github.com/enginestein/Virus-Collection | 2026-08-20 | 1 |
| URL | http://MRS.MAJOR | 2026-08-11 | 1 |
| file sample | index.html | 2026-08-08 | 1 |
| file sample | 250228-v7xgastm19_pw_infected.zip | 2026-08-06 | 1 |
| URL | https://plushyplayground.org/ | 2026-05-11 | 2 |
| file sample | DLLgen.py | 2026-03-29 | 1 |
| file sample | ssl bypass by Rec OGs.dll | 2026-03-15 | 1 |
| file sample | sample | 2026-02-18 | 1 |
Detection coverage
- 151 YARA rules
- 849 Sigma rules
Malware & tools used
- DLL (attack-pattern)
- Remote Data Staging (attack-pattern)
- Scheduled Task (attack-pattern)
- Service Execution (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Valid Accounts (attack-pattern)
- Pass the Hash (attack-pattern)
- Web Protocols (attack-pattern)
- Native API (attack-pattern)
- Domain Controller Authentication (attack-pattern)
- DNS (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Archive via Utility (attack-pattern)
- Windows Remote Management (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Domain Account (attack-pattern)
- Process Discovery (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- PowerShell (attack-pattern)
- NTDS (attack-pattern)
- Local Data Staging (attack-pattern)
- Sharepoint (attack-pattern)
- Network Share Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
Reports & references
- MITRE ATT&CK — G0114 (report)
- cycraft.com — Cycraft Whitepaper Chimera V4.1 (report)
- web.archive.org — Abusing Cloud Services To Fly Under The Radar (report)