ChChes, also known as HAYMAKER and Scorpion, is a modular Windows backdoor associated with the China-linked cyberespionage group APT10, also called menuPass or Stone Panda. It has been used in Japan-focused espionage operations, including the ChessMaster campaign, against academic institutions, pharmaceutical and technology companies, media organizations, managed service providers, government agencies, and manufacturing interests. It commonly provides an initial foothold from which operators load additional modules and extend access to compromised systems.
ChChes collects host and execution-environment information, including the hostname, Windows version, process identifier, working directory, and display resolution. Its modules support shell command execution, file upload and download, DLL loading and execution, and task enumeration. It can steal credentials stored in Internet Explorer and alter proxy configuration. Command-and-control communication uses HTTP Cookie headers with custom Base64 encoding and RC4 encryption involving MD5-derived keys; additional modules support AES-encrypted communications. Registry-based autostart persistence has been observed, although some initial-stage samples lack built-in persistence.
Distribution includes socially engineered spear-phishing emails, document-themed lures, malicious shortcuts, and PowerShell-based execution chains. PowerSploit-derived scripts have injected ChChes into PowerShell, allowing it to operate entirely in memory without saving the implant to disk. Other deployments use reflective loading and runtime packers incorporating XOR and AES. Defense-evasion measures include masquerading as antivirus software and signing samples with a revoked certificate originally used by HackingTeam and exposed following its 2015 breach.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 (patched in September 2017) within the Microsoft .NET framework to download additional malware.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Haymaker - A backdoor that can execute and download other payloads in the form of modules. | ChChes - Trojan that is believed to be used exclusively by APT10.
ChessMaster’s name is from pieces of chess/checkers/draughts we found in the resource section of the main backdoor they use against their targets: ChChes, which Trend Micro detects as BKDR_CHCHES.
While the original campaign was comprehensive and used remote access Trojans (RATs) such as ChChes and RedLeaves, this new campaign used a new backdoor.
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
23 distinct techniques documented for this family, organized by ATT&CK tactic.
上記PowerShellスクリプトによって、指定されているURLからPowerShellスクリプトを含むファイルがダウンロードされます。ダウンロードされたスクリプトは32bitのpowershell.exe(syswow64\WindowsPowerShell\v1.0\powershell)に読み込まれて実行されます。 | ショートカットファイルを開くと内部に含まれている次のPowerShellスクリプトが実行されます。 powershell.exe -nop -w hidden -exec bypass -enc ...
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
次に、PowerShellスクリプト内に含まれるChChesのコード(バージョン1.6.4)が、powershell.exeにインジェクションされ、実行されます。
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
JPCERT also recently analyzed this family and was able to collect modules that give ChChes the following functions: ... Uploading and downloading files Loading and executing the DLL
The data is embedded within the ‘Cookie’ HTTP header... The data embedded within the Cookie header is encrypted using a unique technique.
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as a first-stage backdoor used in APT10 operations during the 2016–2017 resurgence.
Malware that copies itself under deceptive filenames imitating antivirus software.
Malware that persists by adding a Registry Run key.
Backdoor that encrypts C2 traffic using AES or RC4.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.