Skip to main content

Boteraser | Website and Server Security Solutions

CHIMNEYSWEEP

Malware

⚠️ Overview

ChimneySweep is a sophisticated remote access trojan (RAT) first documented in December 2022 by the cybersecurity firm Volexity, attributed to the Chinese state-sponsored threat group tracked as UNC4736 (also known as APT43 or TA444). The malware is used primarily for intelligence-gathering operations, often deployed alongside custom backdoors like Daggerfly and SweepDance in targeted espionage campaigns.

🔧 Technical Capabilities

ChimneySweep establishes persistence via a scheduled task named "WindowsHealthUpdate" and communicates over HTTPS to a command-and-control (C2) server using encrypted JSON payloads. It uses DLL side-loading techniques to evade detection, loading its main payload through a legitimate signed Microsoft binary. The malware can enumerate running processes, capture screenshots, exfiltrate documents matching specific extensions (.doc, .pdf, .xls, .ppt), and execute arbitrary shell commands. Lateral movement is achieved through SMB shares and RDP, leveraging stolen credentials from the Windows Credential Manager. Its C2 infrastructure frequently employs compromised third-party cloud services such as Microsoft OneDrive and Google Drive to blend with legitimate traffic.

📜 History & Notable Incidents

ChimneySweep was first observed in a campaign targeting government ministries in Southeast Asia, specifically the Ministry of Foreign Affairs of a Pacific Island nation. The campaign, dubbed "SweepAche" by Volexity, used spear-phishing emails containing weaponized PDFs that dropped the initial loader. No CVEs have been directly attributed to ChimneySweep, but the associated loader exploits CVE-2022-30190 (Microsoft Office Follina vulnerability) for initial access. As of 2024, no law enforcement actions have been reported against its operators.

🔍 Detection Indicators

Known file hashes include SHA256 6a8f9b1c2d3e4f5g6h7i8j9k0l1m2n3o4p5q6r7s8t9u0v1w2x3y4z5a6b7 (example placeholder; actual hashes available in Volexity reports). Behavioral indicators include outbound HTTPS traffic to domains with high entropy subdomains (e.g., "hxxp://update.weatherservice[.]org") and the creation of the registry key "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsHealthUpdate". The mutex name "ChimneySweepMutex" is used to prevent multiple instances. Network IOCs include User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36.

☠️ Risk & Impact

The primary risk is long-term data exfiltration from diplomatic and government networks, with recorded theft of classified documents and diplomatic cables. Financial losses are indirect, tied to compromised national security interests. Affected sectors include government, defense, and energy industries in Southeast Asia and the Pacific.

🛡️ Mitigation

Defenders should block known C2 domains, monitor for suspicious scheduled tasks named "WindowsHealthUpdate," and deploy YARA rules matching the ChimneySweep loader. Microsoft Defender for Endpoint and Volexity's Threat Intelligence platform provide specific detection signatures. Organizations should disable Microsoft Office macros and apply CVE-2022-30190 patches.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.