ChamelGang, also known as CamoFei, is a suspected China-linked cyberespionage threat group. It has targeted government bodies and critical-infrastructure organizations, including aviation, energy, and health-care entities. Confirmed or strongly assessed victim geography includes Brazil, India, Japan, Russia, Taiwan, and the United States. Notable suspected operations include ransomware incidents against Brazil's presidential administration and India's All India Institute of Medical Sciences in 2022, involving CatB ransomware. The group has also been linked to targeting of an East Asian government organization and an aviation organization in the Indian subcontinent. ChamelGang has used custom malware including BeaconLoader and has overlap with activity involving SHADOWPAD, DOORME, and SIESTAGRAPH implants. Reported tradecraft includes compromise of internet-facing servers, covert web-server backdoors, Microsoft 365-based command-and-control and file transfer, command execution, system and network discovery, screenshot capture, mailbox collection, persistence, DLL side-loading, registry-resident payload storage, and process injection. ChamelGang has deployed ransomware and encryption tooling for a combination of financial gain, operational disruption, attribution misdirection, and removal of forensic evidence; its ransomware use can also obscure espionage activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected Chinese espionage group conducting intrusions against government and critical infrastructure targets and using ransomware/data-encryption tooling, including CatB, in attacks such as those affecting AIIMS and the Presidency of Brazil.
Threat group using ransomware/encryptors across campaigns for mixed objectives: monetization, disruption, and wiping evidence.
Chinese cyberespionage group observed deploying ransomware and encryptors as cover for espionage, disruption, misattribution, evidence removal, and possible financial gain. The content links it to attacks on Brazil’s presidential office and India’s AIIMS healthcare institution.
Activity cluster associated in this content with REF2924 through shared malware, victimology, and strategic targeting, including Exchange server compromises and DOORME deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.