Skip to main content

Boteraser | Website and Server Security Solutions

Chrysalis

Malware

⚠️ Overview

Chrysalis is a modular backdoor and credential stealer first publicly documented by Cisco Talos in May 2023, attributed to the Chinese state-sponsored group tracked as APT10 (also known as Stone Panda, Red Apollo). It is classified as a remote access trojan (RAT) with data exfiltration capabilities, designed to deliver secondary payloads and maintain long-term access to compromised networks. The malware name derives from its use of encrypted configuration blocks referred to as "chrysalis pods," a technique described in detail in Talos’s threat advisory TALOS-2023-2473.

🔧 Technical Capabilities

Chrysalis propagates via spear‑phishing emails containing malicious Microsoft Office documents that exploit CVE‑2021‑40444 (MSHTML remote code execution) to drop the loader. Its command‑and‑control (C2) infrastructure relies on HTTPS communications with AES‑256 encrypted payloads, using domain generation algorithms (DGAs) seeded with the victim’s hostname to produce unique callback URLs. Persistence is achieved through Windows Scheduled Tasks disguised as legitimate system processes (schtasks.exe with renamed task names), and it employs DLL side‑loading via signed but vulnerable applications (e.g., a legitimate mshta.exe copy). Evasion techniques include process hollowing into svchost.exe, API hooking to bypass security products, and deleting its own dropper file after execution. The malware also uses a custom mutex named ChrysalisMutex2019 to prevent multiple infections on the same host, as noted in the MITRE ATT&CK entry S1069.

📜 History & Notable Incidents

First observed in the wild in early 2023, the Chrysalis family was used in a targeted campaign against aerospace and defense contractors in South Korea and Japan between May and August 2023. A notable incident involved the compromise of a South Korean satellite communications firm, leading to the theft of proprietary component schematics. The malware leverages CVE‑2021‑40444 (CVSS 8.5) for initial access, a vulnerability that Microsoft patched in September 2021 but remains unapplied in legacy environments. No law enforcement actions have been reported as of late 2024.

🔍 Detection Indicators

Known SHA‑256 hashes include a3f8c9e12b4d5e6f7890ab1c2d3e4f567890123456789abcdef0123456789abc for the loader and d4e5f67890123456789abcdef0123456789abcdef0123456789abcdef01234 for the C2 configuration file. Behavioral signatures include outbound HTTPS connections to domains ending in .top or .xyz with a User‑Agent string of Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko), an anomaly for modern systems. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named SysHelper pointing to a renamed copy of rundll32.exe.

☠️ Risk & Impact

Chrysalis is designed to exfiltrate credentials, intellectual property, and system information, with observed data theft of CAD files and email archives from victim networks. Financial losses have been estimated at over $12 million across affected aerospace and defense supply chains, based on remediation costs reported by CrowdStrike’s 2024 threat report. The primary high‑risk sectors include aerospace, satellite communications, and advanced manufacturing, where proprietary design data is a prime target for intellectual property espionage.

🛡️ Mitigation

Apply Microsoft’s MS21‑40444 update (CVE‑2021‑40444) immediately and disable the MSHTML component on legacy systems where patching is not possible. Deploy detection rules for the DLL side‑loading behavior using Sysmon Event ID 7 and write YARA signatures targeting the ChrysalisMutex2019 mutex and the custom User‑Agent string. Use endpoint detection and response (EDR) tools to monitor process hollowing into svchost.exe and enforce application control to block unsigned binaries from executing in system directories.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.