Chimera

MITRE ATT&CK: G0114 View on attack.mitre.org

Aliases: Chimera

First seen
2018-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
15 (10 malicious)
Last IoC activity
2026-09-02 02:41:20
Profile updated
2026-07-07 12:30:37

Targeted industries: technology-and-telecommunications transportation-and-logistics

Targeted regions: country_code:tw

Context

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.

Recent IoC activity

10 malicious indicators in Maltiverse are attributed to Chimera (G0114). The 10 most recently updated:

TypeIndicatorUpdatedSources
URL https://github.com/ducat04/ducats-nuker/releases/tag/nuke 2026-09-01 1
file sample Default-Dark-Mode-1.21.11-2026.4.0.zip 2026-08-20 1
URL https://github.com/enginestein/Virus-Collection 2026-08-20 1
URL http://MRS.MAJOR 2026-08-11 1
file sample index.html 2026-08-08 1
file sample 250228-v7xgastm19_pw_infected.zip 2026-08-06 1
URL https://plushyplayground.org/ 2026-05-11 2
file sample DLLgen.py 2026-03-29 1
file sample ssl bypass by Rec OGs.dll 2026-03-15 1
file sample sample 2026-02-18 1

Detection coverage

  • 151 YARA rules
  • 849 Sigma rules

Malware & tools used

  • DLL (attack-pattern)
  • Remote Data Staging (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Service Execution (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Web Protocols (attack-pattern)
  • Native API (attack-pattern)
  • Domain Controller Authentication (attack-pattern)
  • DNS (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Windows Remote Management (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • Process Discovery (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • PowerShell (attack-pattern)
  • NTDS (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Sharepoint (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)

Reports & references

  • MITRE ATT&CK — G0114 (report)
  • cycraft.com — Cycraft Whitepaper Chimera V4.1 (report)
  • web.archive.org — Abusing Cloud Services To Fly Under The Radar (report)

External references