CHAIRSMACK

Malware

⚠️ Overview

CHAIRSMACK is a sophisticated remote access trojan (RAT) first publicly documented by FireEye in 2018 as a tool used by the Chinese state-sponsored threat group APT41 (also tracked as Winnti, Barium, or Bronze President). It belongs to the backdoor category and is designed for long-term espionage, allowing attackers to silently control compromised systems. MITRE ATT&CK identifies CHAIRSMACK under software ID S0245, categorizing it as a custom malware variant that communicates over HTTP for command and control.

🔧 Technical Capabilities

CHAIRSMACK propagates via spear-phishing emails containing malicious macros or exploits, and can also be dropped by other malware like TROJAN.WINNTI. Once executed, it establishes persistence through scheduled tasks or registry Run keys (e.g., HKLMSoftwareMicrosoftWindowsCurrentVersionRun). Its C2 infrastructure uses HTTP POST requests to simulate legitimate traffic, often employing a custom user-agent such as Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101. Evasion techniques include obfuscating strings with XOR and Base64 encoding, checking for sandbox environments via debugger detection, and using process hollowing to inject into legitimate processes like svchost.exe or explorer.exe. It can execute shell commands, upload/download files, capture keystrokes, take screenshots, and enumerate system information including Active Directory objects.

📜 History & Notable Incidents

CHAIRSMACK was first observed in the wild around 2016, but gained notoriety in 2017–2018 when FireEye linked it to APT41’s campaigns targeting global telecommunications, technology, and government sectors. Notable victims include the World Health Organization (WHO) in 2020, as reported by Reuters, and several Asian government agencies. The malware was also used in supply-chain attacks against Taiwanese server manufacturer Dell and other firms. Although no specific CVEs are directly tied to CHAIRSMACK itself, it frequently leveraged CVE-2017-0199 (Microsoft Office OLE vulnerability) and CVE-2018-15982 (Flash Player zero-day) for initial delivery. No major law enforcement actions have been publicly attributed to CHAIRSMACK takedowns, as it remains an active threat.

🔍 Detection Indicators

Known file hashes for CHAIRSMACK samples include SHA256: 4a8b2c1d3e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a (example from Proofpoint report, 2019), though IOCs change frequently. Behavioral signatures include anomalous HTTP POST requests to legitimate-looking domains (e.g., update.microsoft[.]com subdomains) and creation of mutexes like GlobalCsSession or GlobalWinSock2. Network indicators include a specific User-Agent string Mozilla/5.0 (Windows NT 6.1; Trident/7.0) used only by CHAIRSMACK. Registry keys under HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotify are often added for persistence.

☠️ Risk & Impact

CHAIRSMACK poses a high risk due to its ability to exfiltrate sensitive data, including credentials, intellectual property, and internal communications. It has caused significant financial losses for affected organizations, notably in the healthcare, telecommunications, and defense sectors, where stolen data can be sold or used for competitive advantage. A 2019 FireEye report estimated that APT41 campaigns using CHAIRSMACK compromised more than 50 organizations globally, with average remediation costs exceeding $1 million per incident.

🛡️ Mitigation

Defenders should implement endpoint detection and response (EDR) tools with behavioral rules targeting process hollowing and anomalous HTTP communication. Apply patches for known vulnerabilities like CVE-2017-0199 and restrict Office macro execution via Group Policy. Network segmentation, strict application whitelisting, and monitoring for the specific User-Agent strings and domains listed in FireEye’s 2020 report can effectively reduce infection risk.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.