Chaya_005 is a previously undocumented threat cluster focused on internet-exposed industrial and network edge devices, with activity observed for at least two years and notable exploitation recorded in early 2024. The actor has primarily compromised outdated Sierra Wireless industrial routers and later expanded targeting to additional edge-device vendors. Reported operations include weaponization of CVE-2018-4063, an unrestricted file upload vulnerability in Sierra Wireless AirLink ALEOS routers, to deliver a malicious payload and obtain code execution with elevated privileges on affected devices. Available reporting indicates Chaya_005 has conducted broad reconnaissance across multiple vendor vulnerabilities rather than narrowly focused intrusions against a single victim set. The actor’s tradecraft is consistent with scanning for exposed devices, exploiting known vulnerabilities for initial access, and executing post-compromise payload delivery on embedded or edge infrastructure. Industrial routers and similar operational technology-adjacent networking equipment appear to be the primary target class. Chaya_005 has been associated with activity in an ecosystem where compromised routers are commonly used to deploy botnet or cryptominer malware, but high-confidence attribution of a specific downstream malware family or monetization model to this actor remains limited. The cluster is not publicly established as a nation-state actor. Public assessments have also indicated that no further successful exploitation by Chaya_005 was detected after January 2024 and that the actor may no longer represent a significant active threat. No widely used aliases or confirmed sub-groups are established beyond the Chaya_005 designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chaya_005 is a threat actor focused on compromising industrial routers and network edge devices, primarily targeting outdated Sierra Wireless devices.
Chaya_005 is a newly identified threat cluster that conducted a reconnaissance campaign targeting multiple vendor vulnerabilities, including weaponizing CVE-2018-4063 to upload malicious payloads to Sierra Wireless AirLink routers. The campaign appears to have been short-lived and is no longer considered a significant threat.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.