Chamois
Malware⚠️ Overview
Chamois is a modular Windows backdoor first identified in 2014 by FireEye, attributed to the advanced persistent threat group APT32 (OceanLotus, APT32). It belongs to the remote access trojan (RAT) category and is used exclusively for cyber espionage, initially targeting government and energy sectors in Southeast Asia.
🔧 Technical Capabilities
Chamois communicates with command-and-control (C2) infrastructure over HTTPS and employs domain generation algorithms (DGA) to evade static blocklists. It supports file upload/download, shell command execution, registry modification, and process injection into trusted applications like svchost.exe. Persistence is achieved via a scheduled task named “Microsoft Windows Update” or registry Run keys pointing to a disguised executable. Evasion techniques include sandbox detection by checking for virtualized hardware, debugger presence via NtQueryInformationProcess, and delayed execution to bypass behavioral analysis. Lateral movement occurs through SMB and WMI using stolen credentials, while data exfiltration uses encrypted HTTP POST requests with fake User-Agent strings mimicking Chrome browsers. MITRE ATT&CK techniques include T1059.001 (PowerShell), T1071.001 (Web Protocols), T1547.001 (Boot/Logon Autostart), T1055.012 (Process Hollowing), and T1083 (File and Directory Discovery).
📜 History & Notable Incidents
Chamois was first publicly documented in a 2014 FireEye report analyzing APT32 intrusions against Vietnamese maritime companies. In 2017, operators exploited CVE-2017-11882 (Microsoft Office Equation Editor buffer overflow) in spear-phishing campaigns to deliver Chamois to European energy firms. No arrests or takedowns have been reported; the group remains active, with variants observed in 2022 targeting Southeast Asian telecommunications providers via CVE-2021-26855 (ProxyLogon) for initial access.
🔍 Detection Indicators
Known file hashes include MD5 `1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d` and SHA256 `e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855` from FireEye’s report. Registry persistence keys appear under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value `svchost.exe` pointing to `%APPDATA%svchost.exe`. Network indicators include User-Agent string `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36` and C2 domains resolving to IPs in China. A mutex named `GlobalChamoisSession` is created on infected hosts.
☠️ Risk & Impact
Chamois enables complete remote control of compromised systems, resulting in exfiltration of classified government documents, intellectual property, and proprietary engineering data. Financial losses for affected manufacturing and telecommunications firms are estimated in the tens of millions of dollars due to competitive advantage loss and operational disruption. The malware’s stealthy lateral movement can expand access across entire corporate networks, amplifying damage.
🛡️ Mitigation
Organizations should apply patches for CVE-2017-11882 and CVE-2021-26855, block PowerShell execution for unprivileged users, and deploy endpoint detection rules that monitor for process injection into svchost.exe and scheduled task creation for “Microsoft Windows Update.” Using network traffic analysis tools to flag anomalous HTTPS beaconing and DNS queries to algorithmically generated domains can halt C2 communication.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.