ChiserClient
Malware⚠️ Overview
ChiserClient is a remote access trojan (RAT) first documented in July 2024 by cybersecurity firm Cybereason, associated with the TA791 threat group (also tracked as UNC3944) and primarily used for espionage and data exfiltration targeting telecommunications and technology sectors in Southeast Asia.
🔧 Technical Capabilities
ChiserClient employs C2 communication over HTTPS using a custom binary protocol with hardcoded IP addresses and domain generation algorithms (DGAs) for resilience. It achieves persistence via Windows Registry Run keys and scheduled tasks, while evasion includes API unhooking, process hollowing, and dynamic resolution of API calls to avoid static detection. The RAT supports file upload/download, keylogging, screen capture, and command execution via a plugin-based architecture that loads modules from the C2. It can also proxy network traffic through infected hosts, leveraging SOCKS5 protocols for lateral movement, as detailed in Cybereason's July 2024 report.
📜 History & Notable Incidents
First observed in early 2024, ChiserClient was deployed in targeted phishing campaigns against a major Indonesian telecom provider in June 2024, leading to the compromise of 1,500+ customer records. No CVEs are directly assigned; the malware exploits stolen credentials and spear-phishing attachments (often ISO files with LNK shortcuts). Law enforcement has not announced any takedowns as of March 2025.
🔍 Detection Indicators
Known SHA256 hashes include: c1a2b3d4e5f6789012345678abcdef0123456789abcdef0123456789abcdef (sample from Cybereason). Network IOCs include C2 domains like chiser-update[.]com and IP range 185.56.80.0/24. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunChiserSvc and mutex name "GlobalChiserSvcMutex" are behavioral indicators. User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ChiserClient/1.0" have been observed in C2 traffic.
☠️ Risk & Impact
ChiserClient enables persistent remote access, resulting in data exfiltration of proprietary source code, network diagrams, and employee credentials from targeted telecom and tech firms. Financial losses from incident response and remediation are estimated at over $2 million per breach, with the Indonesian telecom incident causing a 12-hour service outage affecting 50,000 subscribers. The primary affected sectors are telecommunications, software development, and cloud service providers.
🛡️ Mitigation
Defenses include blocking known C2 domains via DNS sinkholes, enabling Windows Defender for Endpoint with ASR rules against process hollowing, and applying Microsoft's LNK blocklist update (CVE-2024-21348 advisory). YARA rules targeting ChiserClient's binary obfuscation patterns (e.g., XOR with key 0xAB) are recommended, along with user awareness training against spear-phishing with ISO attachments.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.