Chamelgang
Aliases: CamoFei
- First seen
- 2021-04-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:04:08
Targeted industries: energy-and-utilities technology-and-telecommunications
Context
In Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company. The investigation revealed that the company's network had been compromised by an unknown group for the purpose of data theft. They gave the group the name ChamelGang (from the word "chameleon"), because the group disguised its malware and network infrastructure under legitimate services of Microsoft, TrendMicro, McAfee, IBM, and Google.
Detection coverage
- 145 YARA rules
Malware & tools used
- DoorMe (malware)
- Cobalt Strike (malware)
Reports & references
- ptsecurity.com — New Apt Group Chamelgang (report)
- sentinelone.com — Chamelgang Attacking Critical Infrastructure With Ransomware (report)