ChChes is a Windows backdoor associated closely with the China-linked espionage activity tracked as menuPass, APT10, and Stone Panda, and has also appeared in reporting on the ChessMaster intrusion set targeting organizations in Japan. It has been used primarily as an initial foothold or first-stage implant in targeted intrusions against academia, pharmaceutical organizations, manufacturers, media, technology firms, managed service providers, and government-related entities, especially in Japan. Delivery has been observed through spearphishing, including malicious shortcut files that launch PowerShell, as well as campaigns using socially engineered document lures. In some cases, operators abused PowerSploit to inject ChChes into PowerShell and run it filelessly in memory.
Functionally, ChChes profiles the victim host by collecting basic system and process information, including the process identifier and host environment details, then communicates with command-and-control infrastructure over HTTP. A notable trait is its use of HTTP Cookie headers for command-and-control traffic, with custom encoding and encryption schemes involving Base64 as well as RC4 or AES in different variants and modules. ChChes can receive and load additional code or modules, making it suitable as a staging implant for broader post-compromise activity.
Observed capabilities include theft of credentials stored in Internet Explorer, execution of shell commands through modules, file upload and download, DLL loading and execution, proxy configuration changes, and persistence via Registry Run keys in some variants or deployments. It has also been observed copying itself under names intended to resemble legitimate security software as a masquerading tactic. Multiple reports describe packed and iteratively refined variants, including fileless forms and second-stage versions with differing encrypted communications. ChChes has been described as distinctive tooling within the broader APT10 ecosystem and as an important component of long-running cyber-espionage operations focused on Japanese and other strategic targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 (patched in September 2017) within the Microsoft .NET framework to download additional malware.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition to using PlugX and Poison Ivy (PIVY), both known to be used by the group, they also used a new Trojan called “ChChes” ... ChChes acts as an initial infiltration point on a victim machine. It has the ability to load additional code...
ChessMaster’s name is from pieces of chess/checkers/draughts we found in the resource section of the main backdoor they use against their targets: ChChes, which Trend Micro detects as BKDR_CHCHES.
While the original campaign was comprehensive and used remote access Trojans (RATs) such as ChChes and RedLeaves, this new campaign used a new backdoor.
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers spoofed several sender email addresses to send spear phishing emails, most notably public addresses associated with the Sasakawa Peace Foundation and The White House.
上記PowerShellスクリプトによって、指定されているURLからPowerShellスクリプトを含むファイルがダウンロードされます。ダウンロードされたスクリプトは32bitのpowershell.exe(syswow64\WindowsPowerShell\v1.0\powershell)に読み込まれて実行されます。 | ショートカットファイルを開くと内部に含まれている次のPowerShellスクリプトが実行されます。 powershell.exe -nop -w hidden -exec bypass -enc ...
JPCERT also recently analyzed this family and was able to collect modules that give ChChes the following functions: ... Execute shell command
The ‘Base64-Encoded Data’ field contains a fairly complex structure that will store a module that is to be loaded and subsequently run by ChChes.
ChChes hides part of the decryption key and payload in registry keys to make it harder to reverse engineer.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
次に、PowerShellスクリプト内に含まれるChChesのコード(バージョン1.6.4)が、powershell.exeにインジェクションされ、実行されます。
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Priority MITRE ATT&CK Mapping ... Defense Evasion T1027.013 Encrypted/Encoded File Encoded malware strings and obfuscation
This malware is provided with an icon that appears to be that of a Microsoft Word document.
次に、PowerShellスクリプト内に含まれるChChesのコード(バージョン1.6.4)が、powershell.exeにインジェクションされ、実行されます。
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Examples include: "ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header," "UPPERCUT has used HTTP for C2, including sending error codes in Cookie headers," and "GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2."
インジェクションされたChChesは前号の分析センターだよりで紹介した通り、C2サーバから命令とモジュールを受信します。
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
JPCERT also recently analyzed this family and was able to collect modules that give ChChes the following functions: ... Uploading and downloading files Loading and executing the DLL
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as a first-stage backdoor used in APT10 operations during the 2016–2017 resurgence.
Malware that copies itself under deceptive filenames imitating antivirus software.
Malware that persists by adding a Registry Run key.
Backdoor that encrypts C2 traffic using AES or RC4.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.