Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
59
techniques
6
software
11,554
corpus matches
profile
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
techniques
59 attributed · most-instrumented first
Ingress Tool Transfer
command-and-control
PowerShell
execution
Tool
resource-development
Windows Command Shell
execution
Match Legitimate Resource Name or Location
stealth
Web Protocols
+47 more techniques
software
6 malware & tools attributed
Mimikatz
S0002
PsExec
S0029
Net
S0039
Cobalt Strike
S0154
esentutl
S0404
BloodHound
S0521
read this carefully
11,554 corpus matches is not attribution
That count is indicators which exhibit techniques Chimera is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
command-and-control
showing 30 of 11,554