Intrusion setG0114
Chimera
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
- Documented techniques
- 59
- Assessed origin
- China
- First seen
- 2018
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance1
resource development1
execution6
persistence1
credential access4
discovery18
- T1007 System Service Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1069.001 Local Groups
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1124 System Time Discovery
- T1135 Network Share Discovery
- T1201 Password Policy Discovery
- T1217 Browser Information Discovery
- T1482 Domain Trust Discovery
- T1680 Local Storage Discovery
lateral movement5
collection8
command and control4
defense impairment2
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Cobalt Strike
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.
BloodHoundMimikatzNetPsExecesentutl