THREAT_ACTOR · G0114
Chimera
Also known as: Chimera
Profile
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
MITRE ATT&CK ↗Techniques
59 ATT&CK techniques attributed to this actor.
T1003.003 NTDST1007 System Service DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1021.006 Windows Remote ManagementT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1039 Data from Network Shared DriveT1041 Exfiltration Over C2 ChannelT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1069.001 Local GroupsT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1071.004 DNST1074.001 Local Data StagingT1074.002 Remote Data StagingT1078 Valid AccountsT1078.002 Domain AccountsT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1105 Ingress Tool TransferT1106 Native APIT1110.003 Password SprayingT1110.004 Credential StuffingT1111 Multi-Factor Authentication InterceptionT1114.001 Local Email CollectionT1114.002 Remote Email CollectionT1119 Automated CollectionT1124 System Time DiscoveryT1133 External Remote ServicesT1135 Network Share DiscoveryT1201 Password Policy DiscoveryT1213.002 SharepointT1217 Browser Information DiscoveryT1482 Domain Trust DiscoveryT1550.002 Pass the HashT1556.001 Domain Controller AuthenticationT1560.001 Archive via UtilityT1567.002 Exfiltration to Cloud StorageT1569.002 Service ExecutionT1570 Lateral Tool TransferT1572 Protocol TunnelingT1574.001 DLLT1588.002 ToolT1589.001 CredentialsT1680 Local Storage DiscoveryT1685.005 Clear Windows Event Logs
Software
6 malware/tools attributed to this actor.
MimikatzPsExecNetCobalt StrikeesentutlBloodHound
Related corpus activity
10,221 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Chimera.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,221.