Chamelgang
ChamelGang is a suspected Chinese cyberespionage threat group, also referred to as CamoFei. Reporting in the provided content links the group to espionage-oriented intrusions as well as repeated deployment of ransomware and encryptors for financial gain, disruption, distraction, misattribution, and removal of evidence. Researchers associated ChamelGang with attacks on the Presidency of Brazil and the All India Institute of Medical Sciences in 2022 involving CatB ransomware, and with 2023 targeting of a government organization in East Asia and an aviation organization in the Indian subcontinent. Prior reporting cited in the content also states that ChamelGang has targeted government and private organizations in the United States, Taiwan, and Japan, and impacted critical sectors in Russia, including aviation. Elastic Security Labs assessed REF2924 activity as likely consistent with ChamelGang based on shared malware, file names, techniques, victimology, and strategic targeting priorities, and linked related campaigns with Winnti and ChamelGang with moderate confidence. Malware and tooling mentioned in the content in connection with ChamelGang-linked activity include BeaconLoader, CatB ransomware, the DOORME IIS backdoor, the SIESTAGRAPH .NET implant using Microsoft Graph API, Outlook drafts, and OneDrive for command and control, and a SHADOWPAD loader delivered via DLL sideloading. The content describes associated tradecraft including compromise of internet-facing IIS and Exchange servers, covert remote access, in-memory shellcode execution, file transfer, command execution, screenshots, network discovery, mailbox collection, persistence via services and registry-stored encrypted payloads, and use of ransomware or legitimate encryption tools to conceal or disrupt operations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Health Care Equipment & Services
- Government & Administration
- Transportation
Where they target
Geographies tied to known operations.
- 🇧🇷 Brazil
- 🇮🇳 India
- 🇯🇵 Japan
- 🇷🇺 Russia
- 🇹🇼 Taiwan
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected Chinese espionage group conducting intrusions against government and critical infrastructure targets and using ransomware/data-encryption tooling, including CatB, in attacks such as those affecting AIIMS and the Presidency of Brazil.
Threat group using ransomware/encryptors across campaigns for mixed objectives: monetization, disruption, and wiping evidence.
Chinese cyberespionage group observed deploying ransomware and encryptors as cover for espionage, disruption, misattribution, evidence removal, and possible financial gain. The content links it to attacks on Brazil’s presidential office and India’s AIIMS healthcare institution.
Activity cluster associated in this content with REF2924 through shared malware, victimology, and strategic targeting, including Exchange server compromises and DOORME deployment.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.