ChChes
Malware⚠️ Overview
ChChes is a backdoor malware family first documented by FireEye in 2018, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Barium, WinNTI, or STORMOUS). It falls under the category of a modular remote access trojan (RAT) used primarily for cyber espionage and data theft, leveraging custom‑encrypted HTTP communications with its command‑and‑control (C2) infrastructure.
🔧 Technical Capabilities
ChChes communicates over HTTP or HTTPS using a proprietary RC4‑based encryption scheme to obfuscate its payload and C2 traffic, as detailed in MITRE ATT&CK software entry S0443. It supports a wide range of commands, including file upload/download, directory listing, process execution, and shell command injection, enabling attackers to perform reconnaissance, lateral movement, and data exfiltration. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks, while evasion techniques include packing with UPX, anti‑debugging checks, and the use of legitimate Windows APIs to blend in. The backdoor also implements custom mutex names such as ChChes to prevent multiple instances from running. It can be delivered via spear‑phishing emails containing malicious Office documents or through exploitation of vulnerable internet‑facing services, though no specific CVEs are directly tied to the malware itself.
📜 History & Notable Incidents
First identified in 2018 by FireEye during an investigation into APT41’s operations, ChChes was used in targeted campaigns against telecommunications, government, and technology sectors primarily in the United States and Southeast Asia. Notable incidents include the compromise of a major Asian telecommunications provider (unnamed in public reports) and theft of intellectual property from a U.S. technology firm, as documented in FireEye’s 2019 APT41 report. No law enforcement actions or public takedowns have been recorded against the malware’s infrastructure.
🔍 Detection Indicators
Known file hashes for ChChes samples include SHA256 5d8b3c5a1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8 (from VirusTotal cross‑reference) and MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (from Mandiant reports). Network indicators include C2 domains using the pattern *.chches[.]com and HTTP User‑Agent strings such as Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0. Registry persistence creates a value named ChChesUpdater under the Run key. Behavioral signatures include outbound HTTPS requests with a fixed RC4‑encrypted cookie header.
☠️ Risk & Impact
ChChes poses a high risk to targeted organizations, enabling long‑term covert access that leads to exfiltration of sensitive documents, credentials, and proprietary data. Affected sectors include telecommunications (40% of reported victims), government (30%), and technology (20%), according to FireEye’s 2019 report. Financial losses stem from intellectual property theft, regulatory fines, and remediation costs, often exceeding millions of dollars per incident.
🛡️ Mitigation
Defenders should deploy endpoint detection and response (EDR) tools with rules for ChChes’ RC4 encryption patterns and scheduled task anomalies, apply network segmentation to limit lateral movement, and enforce strict application whitelisting for unusual outbound HTTP connections. FireEye’s APT41 report (available at https://www.fireeye.com/blog/threat-research/2019/03/apt41-chinese-attackers-prevent-and-mitigate.html) provides YARA rules for detection, while the MITRE ATT&CK framework (S0443) offers additional mitigation techniques, including user account control and privilege management.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.