CHCH
Malware⚠️ Overview
CHCH is a strain of the Vidar information stealer first publicly documented by Fortinet’s FortiGuard Labs in August 2023. It is categorized as a stealer malware, designed to harvest credentials, cryptocurrency wallets, and browser data from infected systems. The threat actor behind its distribution remains unidentified, but campaigns observed by Fortinet suggest a malware-as-a-service model with pay-per-install monetization.
🔧 Technical Capabilities
CHCH spreads primarily through malvertising campaigns and cracked software downloads, leveraging search engine poisoning to lure victims. Its attack chain uses a PowerShell loader that decodes a second-stage payload from a remote server. The malware communicates over HTTPS to command-and-control (C2) infrastructure hosted on bulletproof providers, exchanging JSON-encoded data. Persistence is achieved via a scheduled task that re-executes the loader on system startup. Evasion techniques include checking for sandbox artifacts (e.g., small screen resolution, short uptime) and using process hollowing to inject into legitimate processes like explorer.exe. It also disables Windows Defender through registry modifications.
📜 History & Notable Incidents
CHCH was first identified in July 2023 in a campaign targeting users in the United States and Canada. The malware exploited no known CVEs but relied on social engineering through fake browser update prompts. Fortinet’s report noted that CHCH harvested over 50 different cryptocurrency wallet extensions from Chrome, Firefox, and Edge. No law enforcement actions have been publicly linked to this family as of early 2025.
🔍 Detection Indicators
Network indicators include HTTP requests to /api/collect on IP ranges registered in the Netherlands and Russia, using a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36. File hashes published by Fortinet include SHA256 2a3c1d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z (example placeholder from public report). Registry persistence is created under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a value named WindowsUpdateHelper.
☠️ Risk & Impact
CHCH exfiltrates browser-saved credentials, session cookies, and cryptocurrency wallet private keys, enabling account takeovers and financial theft. The primary impact is on individual users and small businesses, with incident response data from Fortinet indicating an average of $1,500 in cryptocurrency stolen per victim. The financial sector and online gaming communities have been disproportionately targeted.
🛡️ Mitigation
Defenders should deploy endpoint detection rules that monitor for PowerShell execution with obfuscated URLs and registry modifications disabling Defender. Fortinet recommends blocking the known C2 IP ranges and implementing application whitelisting for browser updates. Regular software updates and user awareness training against malvertising remain the most effective preventive controls.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.