Red Charon (Chimera) is an APT group of unknown origin targeting Taiwan's high-tech companies.
Analyst brief
Red Charon (also tracked as Chimera) is an APT group of unknown origin that targeted Taiwan's high-tech ecosystem throughout 2019. This actor primarily focuses on high-tech companies. Their TTPs include the use of a skeleton key malware that synthesizes code from both Dumpert and Mimikatz. Defenders should pay attention to credential theft countermeasures and anomalous authentication attempts across the network.
Red Charon
unknown
Throughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks having similar behavior profiles (similar adversarial techniques, tactics, and procedures or TTP) with each other and previously documented cyberattacks, CyCraft assess with high confidence these new attacks were conducted by the same foreign threat actor. During their investigation, they dubbed this threat actor Chimera. “Chimera” stands for the synthesis of hacker tools that they’ve seen the group use, such as the skeleton key malware that contained code extracted from both Dumpert and Mimikatz — hence Chimera. Their operation — the entirety of the new attacks utilizing the Skeleton Key attack (described below) from late 2018 to late 2019, CyCraft have dubbed Operation Skeleton Key.