ChChes is a malware family also referred to as Haymaker and Scorpion in the provided content, though ChChes is the most commonly used name. It surfaced in late 2016 and is described as a relatively limited-functionality backdoor designed to establish an initial foothold and perform system fingerprinting. The malware has been associated with APT10 / MenuPass / Red Apollo activity, and reporting in the content notes it was used alongside tools such as PlugX, Poison Ivy, RedLeaves, ANEL/UPPERCUT, QuasarRAT, and Cobalt Strike. One source in the content states ChChes appears to be unique to that group.
Observed infection vectors in the content include spear-phishing or malicious files requiring user execution; one cited example states that when a recipient executes the file, the machine is infected with ChChes. The malware communicates with command-and-control servers over HTTP and embeds data in the HTTP Cookie header. It can encode C2 data using a custom technique that utilizes Base64, and can encrypt C2 traffic with AES or RC4.
Capabilities directly mentioned in the content include altering the victim's proxy configuration, stealing credentials stored in Internet Explorer, and copying itself to an executable filename intended to resemble Norton Antivirus with transposed letters, such as notron.exe. The content also notes that some ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and revoked.
High-confidence behavioral indicators from the content therefore include HTTP-based C2 using Cookie headers, Base64-based custom C2 encoding, AES or RC4-encrypted C2 traffic, Internet Explorer credential theft, proxy configuration changes, and self-copying to deceptive filenames such as notron.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That same reporting identified new or expanded tooling, including HAYMAKER, SNUGRIDE, BUGJUICE, SOGU, and customized QUASARRAT. | FBI’s FLASH explicitly presents the APT10 indicators as high-confidence and includes REDLEAVES, UPPERCUT/ANEL, and CHCHES hash artifacts.
Tools QuasarRAT, RedLeaves, PoisonIvy, ChChes, QuasarRAT Loader, PlugX, ANEL, Cobalt Strike
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The code is heavily obfuscated, via the use of position-independence alongside other techniques.
Priority MITRE ATT&CK Mapping ... Defense Evasion T1027.013 Encrypted/Encoded File Encoded malware strings and obfuscation
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
It attempts to inject into running processes, focussing on security products and native Windows processes.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
It also conducts basic victim profiling activity, collecting the computer name, running process IDs...
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Examples include: "ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header," "UPPERCUT has used HTTP for C2, including sending error codes in Cookie headers," and "GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2."
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ChChes can alter the victim's proxy configuration... MuddyWater can disable the system's local proxy settings... During Night Dragon, the actors also disabled proxy settings to allow direct communication from victims to the Internet.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
"Encrypt communication using AES"; "communication with C&C servers after this point will be encrypted in AES on top of the existing encryption method."
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
105 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as a first-stage backdoor used in APT10 operations during the 2016–2017 resurgence.
Backdoor malware that can modify proxy settings on compromised hosts.
Malware/backdoor referenced as used in spear-phishing compromises of MSPs to enable access for espionage operations.
ChChes used a leaked and later revoked certificate for code signing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.