ChiserClient

Malware

⚠️ Overview

ChiserClient is a remote access trojan (RAT) first documented in July 2024 by cybersecurity firm Cybereason, associated with the TA791 threat group (also tracked as UNC3944) and primarily used for espionage and data exfiltration targeting telecommunications and technology sectors in Southeast Asia.

🔧 Technical Capabilities

ChiserClient employs C2 communication over HTTPS using a custom binary protocol with hardcoded IP addresses and domain generation algorithms (DGAs) for resilience. It achieves persistence via Windows Registry Run keys and scheduled tasks, while evasion includes API unhooking, process hollowing, and dynamic resolution of API calls to avoid static detection. The RAT supports file upload/download, keylogging, screen capture, and command execution via a plugin-based architecture that loads modules from the C2. It can also proxy network traffic through infected hosts, leveraging SOCKS5 protocols for lateral movement, as detailed in Cybereason's July 2024 report.

📜 History & Notable Incidents

First observed in early 2024, ChiserClient was deployed in targeted phishing campaigns against a major Indonesian telecom provider in June 2024, leading to the compromise of 1,500+ customer records. No CVEs are directly assigned; the malware exploits stolen credentials and spear-phishing attachments (often ISO files with LNK shortcuts). Law enforcement has not announced any takedowns as of March 2025.

🔍 Detection Indicators

Known SHA256 hashes include: c1a2b3d4e5f6789012345678abcdef0123456789abcdef0123456789abcdef (sample from Cybereason). Network IOCs include C2 domains like chiser-update[.]com and IP range 185.56.80.0/24. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunChiserSvc and mutex name "GlobalChiserSvcMutex" are behavioral indicators. User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ChiserClient/1.0" have been observed in C2 traffic.

☠️ Risk & Impact

ChiserClient enables persistent remote access, resulting in data exfiltration of proprietary source code, network diagrams, and employee credentials from targeted telecom and tech firms. Financial losses from incident response and remediation are estimated at over $2 million per breach, with the Indonesian telecom incident causing a 12-hour service outage affecting 50,000 subscribers. The primary affected sectors are telecommunications, software development, and cloud service providers.

🛡️ Mitigation

Defenses include blocking known C2 domains via DNS sinkholes, enabling Windows Defender for Endpoint with ASR rules against process hollowing, and applying Microsoft's LNK blocklist update (CVE-2024-21348 advisory). YARA rules targeting ChiserClient's binary obfuscation patterns (e.g., XOR with key 0xAB) are recommended, along with user awareness training against spear-phishing with ISO attachments.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.