Chimera
Aliases: None listed
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
Open interactive actor investigation
ATT&CK techniques
T1574.002
DLL Side-LoadingT1074.002
Remote Data StagingT1053.005
Scheduled TaskT1569.002
Service ExecutionT1041
Exfiltration Over C2 ChannelT1078
Valid AccountsT1550.002
Pass the HashT1071.001
Web ProtocolsT1106
Native APIT1556.001
Domain Controller AuthenticationT1070.001
Clear Windows Event LogsT1071.004
DNST1482
Domain Trust DiscoveryT1560.001
Archive via UtilityT1021.006
Windows Remote ManagementT1083
File and Directory DiscoveryT1087.002
Domain AccountT1057
Process DiscoveryT1021.002
SMB/Windows Admin SharesT1059.001
PowerShellT1003.003
NTDST1074.001
Local Data StagingT1213.002
SharepointT1135
Network Share DiscoveryT1036.005
Match Legitimate Name or LocationT1570
Lateral Tool TransferT1007
System Service DiscoveryT1027.010
Command ObfuscationT1016
System Network Configuration DiscoveryT1046
Network Service DiscoveryT1033
System Owner/User DiscoveryT1087.001
Local AccountT1572
Protocol TunnelingT1078.002
Domain AccountsT1069.001
Local GroupsT1124
System Time DiscoveryT1201
Password Policy DiscoveryT1049
System Network Connections DiscoveryT1059.003
Windows Command ShellT1070.004
File DeletionT1110.003
Password SprayingT1114.001
Local Email CollectionT1039
Data from Network Shared DriveT1119
Automated CollectionT1133
External Remote ServicesT1110.004
Credential StuffingT1082
System Information DiscoveryT1114.002
Remote Email CollectionT1012
Query RegistryT1588.002
ToolT1567.002
Exfiltration to Cloud StorageT1070.006
TimestompT1018
Remote System DiscoveryT1589.001
CredentialsT1047
Windows Management InstrumentationT1021.001
Remote Desktop ProtocolT1111
Multi-Factor Authentication InterceptionT1217
Browser Information DiscoveryT1105
Ingress Tool TransferT1102
Web Service
DLL Side-LoadingT1074.002
Remote Data StagingT1053.005
Scheduled TaskT1569.002
Service ExecutionT1041
Exfiltration Over C2 ChannelT1078
Valid AccountsT1550.002
Pass the HashT1071.001
Web ProtocolsT1106
Native APIT1556.001
Domain Controller AuthenticationT1070.001
Clear Windows Event LogsT1071.004
DNST1482
Domain Trust DiscoveryT1560.001
Archive via UtilityT1021.006
Windows Remote ManagementT1083
File and Directory DiscoveryT1087.002
Domain AccountT1057
Process DiscoveryT1021.002
SMB/Windows Admin SharesT1059.001
PowerShellT1003.003
NTDST1074.001
Local Data StagingT1213.002
SharepointT1135
Network Share DiscoveryT1036.005
Match Legitimate Name or LocationT1570
Lateral Tool TransferT1007
System Service DiscoveryT1027.010
Command ObfuscationT1016
System Network Configuration DiscoveryT1046
Network Service DiscoveryT1033
System Owner/User DiscoveryT1087.001
Local AccountT1572
Protocol TunnelingT1078.002
Domain AccountsT1069.001
Local GroupsT1124
System Time DiscoveryT1201
Password Policy DiscoveryT1049
System Network Connections DiscoveryT1059.003
Windows Command ShellT1070.004
File DeletionT1110.003
Password SprayingT1114.001
Local Email CollectionT1039
Data from Network Shared DriveT1119
Automated CollectionT1133
External Remote ServicesT1110.004
Credential StuffingT1082
System Information DiscoveryT1114.002
Remote Email CollectionT1012
Query RegistryT1588.002
ToolT1567.002
Exfiltration to Cloud StorageT1070.006
TimestompT1018
Remote System DiscoveryT1589.001
CredentialsT1047
Windows Management InstrumentationT1021.001
Remote Desktop ProtocolT1111
Multi-Factor Authentication InterceptionT1217
Browser Information DiscoveryT1105
Ingress Tool TransferT1102
Web Service