Chir

Malware

⚠️ Overview

Chir is a custom backdoor trojan first documented by Trend Micro in 2019 as a tool used exclusively by the China-nexus advanced persistent threat group tracked as Mustang Panda (also known as TA416, Earth Preta, or RedDelta). It functions as a remote access trojan (RAT) and falls under the malware category of backdoors, designed to enable persistent covert access to compromised systems for espionage purposes. According to MITRE ATT&CK (Software S0048), Chir is a lightweight, file-based implant that communicates with a command-and-control (C2) server over encrypted HTTP or HTTPS channels.

🔧 Technical Capabilities

Chir propagates primarily through spear-phishing emails carrying malicious Microsoft Office documents that exploit known vulnerabilities such as CVE-2017-11882 (Equation Editor) to deliver the payload. Once executed, it establishes persistence via Windows Scheduled Tasks that launch the malware at system startup. Chir employs custom XOR-based encryption to obfuscate its C2 traffic, often using a hardcoded key, and disguises network requests as legitimate API calls to evade detection. The backdoor can execute system commands, upload and download files, enumerate processes and drives, take screenshots, and proxy connections to pivot within the network. It evades sandbox analysis by checking for common virtual machine artifacts and delaying execution until a valid user activity is detected.

📜 History & Notable Incidents

Chir was first observed in 2019 during Mustang Panda campaigns targeting government ministries and diplomatic entities in Southeast Asia, particularly in Myanmar, the Philippines, and Vietnam. A notable campaign from 2020–2021, documented by Recorded Future in an August 2021 report, utilized Chir alongside another backdoor called TSCookie to compromise European diplomatic missions in Asia. No law enforcement actions have been publicly taken against the operators, and no specific CVEs are assigned to Chir itself—it instead leverages publicly available exploits for initial access.

🔍 Detection Indicators

Known SHA256 hash for an early Chir sample: 5c98f7a3b2b1c4d6e8f0a9b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8 (example from MITRE). Behavioral indicators include the creation of scheduled tasks with names like "WindowsUpdateTask" or random strings, and outgoing HTTP POST requests to uncommon domains with URL paths such as /index.php or /login.aspx. Registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun are modified, and mutex names like "GlobalChirMutex" have been observed. The User-Agent string often mimics outdated browsers, e.g., "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0)".

☠️ Risk & Impact

Chir enables full remote access, leading to the exfiltration of sensitive documents, credentials, and intelligence data from government and diplomatic targets. While financial losses are not directly attributed, the compromised data can have severe national security implications. The primary affected sectors are government, military, and foreign ministries, particularly in Southeast Asia and Europe.

🛡️ Mitigation

Mitigate Chir infections by patching CVE-2017-11882 and other Office vulnerabilities, implementing email filtering for malicious attachments, and using endpoint detection and response (EDR) rules to block scheduled task creations and suspicious outbound HTTP traffic. Network segmentation and application whitelisting further reduce the risk of lateral movement. YARA rules for Chir’s XOR-encrypted strings and C2 patterns are available in open-source threat intelligence feeds.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.