Chamelgang is a threat group targeting energy and aviation sectors, known for data theft by disguising as legitimate services.
Analyst brief
Chamelgang (also known as CamoFei) is an unknown threat group discovered in 2021, primarily targeting the energy and aviation sectors. The group disguises its malware and network infrastructure under the names of legitimate services like Microsoft, TrendMicro, McAfee, IBM, and Google to conduct data theft. Their targeting scope includes entities in India, Japan, Nepal, Russia, Taiwan, and the United States. Defenders should focus on detecting processes masquerading as legitimate services, scrutinizing anomalous certificate usage, and monitoring for irregular network traffic indicative of such disguised C2 channels.
Chamelgang
CamoFei
unknown
In Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company. The investigation revealed that the company's network had been compromised by an unknown group for the purpose of data theft. They gave the group the name ChamelGang (from the word "chameleon"), because the group disguised its malware and network infrastructure under legitimate services of Microsoft, TrendMicro, McAfee, IBM, and Google.