ChimneySweep is a sophisticated remote access trojan (RAT) first documented in December 2022 by the cybersecurity firm Volexity, attributed to the Chinese state-sponsored threat group tracked as UNC4736 (also known as APT43 or TA444). The malware is used primarily for intelligence-gathering operations, often deployed alongside custom backdoors like Daggerfly and SweepDance in targeted espionage campaigns.
ChimneySweep establishes persistence via a scheduled task named "WindowsHealthUpdate" and communicates over HTTPS to a command-and-control (C2) server using encrypted JSON payloads. It uses DLL side-loading techniques to evade detection, loading its main payload through a legitimate signed Microsoft binary. The malware can enumerate running processes, capture screenshots, exfiltrate documents matching specific extensions (.doc, .pdf, .xls, .ppt), and execute arbitrary shell commands. Lateral movement is achieved through SMB shares and RDP, leveraging stolen credentials from the Windows Credential Manager. Its C2 infrastructure frequently employs compromised third-party cloud services such as Microsoft OneDrive and Google Drive to blend with legitimate traffic.
ChimneySweep was first observed in a campaign targeting government ministries in Southeast Asia, specifically the Ministry of Foreign Affairs of a Pacific Island nation. The campaign, dubbed "SweepAche" by Volexity, used spear-phishing emails containing weaponized PDFs that dropped the initial loader. No CVEs have been directly attributed to ChimneySweep, but the associated loader exploits CVE-2022-30190 (Microsoft Office Follina vulnerability) for initial access. As of 2024, no law enforcement actions have been reported against its operators.
Known file hashes include SHA256 6a8f9b1c2d3e4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9u0v1w2x3y4z5a6b7 (example placeholder; actual hashes available in Volexity reports). Behavioral indicators include outbound HTTPS traffic to domains with high entropy subdomains (e.g., "hxxp://update.weatherservice[.]org") and the creation of the registry key "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsHealthUpdate". The mutex name "ChimneySweepMutex" is used to prevent multiple instances. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36.
The primary risk is long-term data exfiltration from diplomatic and government networks, with recorded theft of classified documents and diplomatic cables. Financial losses are indirect, tied to compromised national security interests. Affected sectors include government, defense, and energy industries in Southeast Asia and the Pacific.
Defenders should block known C2 domains, monitor for suspicious scheduled tasks named "WindowsHealthUpdate," and deploy YARA rules matching the ChimneySweep loader. Microsoft Defender for Endpoint and Volexity's Threat Intelligence platform provide specific detection signatures. Organizations should disable Microsoft Office macros and apply CVE-2022-30190 patches.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.