FORENSIA

THREAT_ACTOR · G0114

Chimera

Also known as: Chimera

Profile

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.

MITRE ATT&CK ↗

Techniques

59 ATT&CK techniques attributed to this actor.

T1003.003 NTDST1007 System Service DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1021.006 Windows Remote ManagementT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1039 Data from Network Shared DriveT1041 Exfiltration Over C2 ChannelT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1069.001 Local GroupsT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1071.004 DNST1074.001 Local Data StagingT1074.002 Remote Data StagingT1078 Valid AccountsT1078.002 Domain AccountsT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1105 Ingress Tool TransferT1106 Native APIT1110.003 Password SprayingT1110.004 Credential StuffingT1111 Multi-Factor Authentication InterceptionT1114.001 Local Email CollectionT1114.002 Remote Email CollectionT1119 Automated CollectionT1124 System Time DiscoveryT1133 External Remote ServicesT1135 Network Share DiscoveryT1201 Password Policy DiscoveryT1213.002 SharepointT1217 Browser Information DiscoveryT1482 Domain Trust DiscoveryT1550.002 Pass the HashT1556.001 Domain Controller AuthenticationT1560.001 Archive via UtilityT1567.002 Exfiltration to Cloud StorageT1569.002 Service ExecutionT1570 Lateral Tool TransferT1572 Protocol TunnelingT1574.001 DLLT1588.002 ToolT1589.001 CredentialsT1680 Local Storage DiscoveryT1685.005 Clear Windows Event Logs

Software

6 malware/tools attributed to this actor.

MimikatzPsExecNetCobalt StrikeesentutlBloodHound

Related corpus activity

10,221 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Chimera.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,221.