Chimera
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
Chimera is a suspected China-based cyberespionage group targeting Taiwan's semiconductor and airline industries.
Chimera is a suspected China-based threat group active since at least 2018. The group primarily targets the semiconductor industry in Taiwan and data from the airline industry. They utilize tools such as Cobalt Strike, Mimikatz, BloodHound, and PsExec, employing techniques like stealing valid credentials, Pass the Hash, and DLL side-loading to exfiltrate data to cloud storage. Defenders should focus on hardening access controls for external remote services, monitoring for suspicious execution methods like Scheduled Tasks and Service Execution, and be especially vigilant against unauthorized access attempts to the NTDS.dit file.
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
Implement account activity monitoring to detect suspicious Credentials collection activities.
Enhance network traffic monitoring to detect Tool acquisition or download attempts.
Configure endpoint logging and monitoring to track Scheduled Task creation and Service Execution activities.
Restrict remote access and enforce strong authentication policies to limit External Remote Services usage.
Monitor abnormal account activity to detect misuse of Valid Accounts and implement software updates to prevent DLL sideloading.
Monitor NTDS.dat changes on Domain Controllers to detect credential dumping attempts from NTDS.
Monitor LDAP and other directory service queries to detect Domain Trust Discovery activities.
Monitor NTLM authentication attempts and hash usage to detect Pass the Hash attacks.
Monitor file system and network activity to detect Remote Data Staging and Archive via Utility activities.
Implement network traffic monitoring and anomaly detection to identify C2 communication using Web Protocols.
Monitor suspicious network and cloud storage activity to detect Exfiltration Over C2 Channel and Exfiltration to Cloud Storage activities.
Monitor Domain Controller authentication logs and activity to detect attempts to subvert Domain Controller Authentication.
Chimera primarily targets the semiconductor industry in Taiwan and the airline sector.
The group uses tools such as Cobalt Strike, Mimikatz, BloodHound, and PsExec.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.