CHIMNEYSWEEP is a Windows backdoor associated with destructive intrusion activity that also deployed ROADSWEEP ransomware and a ZEROCLEAR variant against targets in Albania. It has been delivered by a signed self-extracting dropper and functions as a surveillance and remote-access implant. Documented capabilities include screenshot capture, file collection and directory listing, clipboard capture, keylogging, removable-drive monitoring, reverse shell access, and uploading collected files to command-and-control infrastructure. It also transmits host-identifying information such as the victim computer name and username in its command traffic.
The malware includes multiple privilege-escalation and execution-enablement features. It can abuse the Windows SilentCleanup scheduled task to run payloads with elevated privileges, use CMSTP-based techniques, invoke PowerShell to execute secondary payloads, and extract RC4-encrypted embedded payloads used during escalation. It also checks whether Deep Freeze is present on the compromised host, suggesting environment awareness prior to follow-on actions.
For defense evasion and anti-forensics, CHIMNEYSWEEP can timestomp its executable to make it appear older and can store captured screenshots in covert temporary files. Its operators have also used public services such as Telegram, Discord, and Dropbox as command-and-control channels, a tradecraft choice that helps blend malicious traffic with legitimate platform usage. The malware can additionally reboot or shut down the system or log off the current user, supporting operational control and disruption.
CHIMNEYSWEEP is best characterized as a backdoor focused on persistent remote access, collection, and post-compromise operator control on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Technical Annex C: CHIMNEYSWEEP Backdoor... CHIMNEYSWEEP has the following major functionality: Screenshot collection... File collection and listing... Keylogging... Reverse shell.
...destructive cyber attacks targeting Albania with a ransomware strain called ROADSWEEP, the CHIMNEYSWEEP backdoor...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. CHIMNEYSWEEP can make use of the Windows SilentCleanup scheduled task to execute its payload with elevated privileges. CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. CHIMNEYSWEEP can make use of the Windows SilentCleanup scheduled task to execute its payload with elevated privileges. CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. CHIMNEYSWEEP can make use of the Windows SilentCleanup scheduled task to execute its payload with elevated privileges. CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.
If the backdoor is not running as an administrator, the backdoor may use embedded payloads to escalate privileges... The module utilises the following techniques to execute the payload as administrator
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
the payload is created by writing the content to the Windows %TEMP% directory with the name APPX.<random_values>.tmp... If the process name contains 'creensaver.', the backdoor will write the image to %SYSTEM32%\Slui
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
CHIMNEYSWEEP can use the Windows SilentCleanup scheduled task to enable payload execution.
the payload uses the Windows Registry Environment key to change the %windir% variable to point to c:\Windows.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
File collection and listing: Monitors for new removable drives and performs directory listing on demand, enumerates directories for files that match a set list
The content repeatedly describes malware and threat actors identifying, monitoring, or enumerating connected peripheral devices such as USB mass storage, Bluetooth devices, printers, smart card readers, cameras, Apple devices, VGA/display devices, and removable drives.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
Keylogging: Monitors the content of the clipboard and performs key logging to disk.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
This export is responsible for all the command-and-control (C&C) interactions and backdoor capabilities... C&C servers: telegram-update[.]com avira[.]ltd windowsupadates[.]com
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CHIMNEYSWEEP is a malware family known for using public platforms like Dropbox for command and control.
Named as an example malware family that uses public platforms (e.g., Dropbox/Discord/Telegram) for command-and-control blending.
Named as an example of malware or intrusion activity using public platforms for command-and-control communications.
Malware capable of timestomping its executable by backdating timestamps across a broad date range.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.