ChessMaster is a cyberespionage campaign focused on organizations in Japan. Reported targets include academia, technology enterprises, media organizations, managed service providers, and government agencies. The operation is associated with spear-phishing activity that uses decoy documents and multi-stage malware delivery chains to establish access and expand within victim environments. The campaign is centered on the ChChes backdoor, a malware family whose naming is derived from chess and draughts references embedded in its resources. ChChes has been delivered through malicious shortcut files and PowerShell-based infection chains, including reflective loading that enables fileless execution. Additional delivery methods have included self-extracting archives that deploy multiple components and abuse DLL hijacking and code injection into legitimate processes. ChChes was observed using multiple runtime packers over time, including progressively more complex obfuscation and encryption layers, indicating iterative refinement for defense evasion. ChessMaster also deployed second-stage ChChes variants with distinct encrypted command-and-control schemes, and used other malware and tooling including TinyX and RedLeaves. TinyX is a PlugX-derived remote access tool variant without plug-in functionality. RedLeaves has been used as a second-stage backdoor to support lateral movement, and variants such as himawari were developed to evade existing detection logic. The campaign additionally misused and modified legitimate credential recovery and dumping tools, enabling credential theft and follow-on movement inside compromised environments. Multiple overlaps have been reported between ChessMaster and APT10, also known as menuPass, POTASSIUM, Stone Panda, Red Apollo, and CVNX. These overlaps include similar targeting, spear-phishing tradecraft, shared or closely related infrastructure patterns, exclusive packers, and comparable use of information-stealing backdoors and legitimate or open-source remote administration tools. ChChes has also been noted to resemble the Emdivi backdoor in its use of the victim system's Security Identifier as part of its encryption logic. ChessMaster is best characterized as a Japan-focused espionage operation with strong reported links to APT10.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
While ChessMaster still uses the previous exploit, it also added more methods to its arsenal: one exploits another vulnerability, CVE-2017-11882 (patched in November 2017), which was also exploited to deliver illegal versions of the Loki infostealer.
When we tracked ChessMaster back in November, we noted that it exploited the SOAP WSDL parser vulnerability CVE-2017-8759 (patched in September 2017) within the Microsoft .NET framework to download additional malware.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyberespionage campaign targeting organizations in Japan using spear-phishing emails with decoy documents, the ChChes backdoor, additional second-stage payloads, credential dumping tools, and lateral movement.
Mentioned as an example of a threat actor using dynamic DNS providers for infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.