Chaes is a Brazil-focused banking trojan targeting Windows systems, first publicly reported in 2020 and later observed at scale in campaigns affecting Brazilian users. It is designed to steal credentials and financial information from Google Chrome and to intercept or manipulate sessions involving Brazilian banking, e-commerce, and payment services. The malware has been associated with multi-stage infection chains and browser-focused fraud operations rather than broad destructive activity.
Chaes has been distributed through compromised websites, particularly WordPress sites, where victims were presented with a fake Java Runtime installer lure. Infection required user interaction to execute the malicious installer or document stage. Observed delivery chains used multiple technologies, including JScript, VBScript, Python, Node.js, Delphi components, and malicious Chrome extensions. The malware family has also used staged decryption and loading, including AES-decrypted components and subsequent retrieval of additional payloads.
Functionally, Chaes combines credential theft with browser surveillance and banking-trojan behavior. It can steal browser-stored login credentials and financial data, collect victim profiling information such as username and host identifiers, capture screenshots, and communicate with command-and-control infrastructure using Base64-encoded traffic. Some components have provided browser automation and control capabilities to monitor or interfere with victim interactions on targeted financial and commerce platforms.
Chaes uses several persistence and evasion mechanisms on Windows. It stores configuration data in the Windows Registry, modifies Registry values for persistence, and has been observed using Run-key style autostart. It has also used DLL search order hijacking with a crafted unsigned DLL masquerading as a legitimate Windows library, alongside script-based execution. Overall, Chaes is a modular banking trojan centered on credential theft, browser compromise, and financial fraud against Brazilian users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
In our investigation, we found the malware is distributed through many compromised websites, including highly credible sites... All compromised websites are WordPress sites... When someone reaches a website compromised by Chaes, they are presented with the below pop-up asking users to install the Java Runtime application.
ChaesCore — that is responsible for setting persistence using Schedule Task and migrating into targeted processes.
Chaes is characterized by the multiple-stage delivery that utilizes scripting frameworks such as JScript, Python, and NodeJS... mtps4 is a backdoor written in Delphi. Its main purpose is to connect to CnC and wait for a responding PascalScript to execute.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
ChaesCore — that is responsible for setting persistence using Schedule Task and migrating into targeted processes.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ChaesCore — that is responsible for setting persistence using Schedule Task and migrating into targeted processes.
ChaesCore — that is responsible for setting persistence using Schedule Task and migrating into targeted processes.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Added layers of encryption and increased stealth capabilities
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
ChaesCore — that is responsible for setting persistence using Schedule Task and migrating into targeted processes.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The Google Chrome extensions are able to steal users’ credentials stored in Chrome and intercept logins of popular banking websites in Brazil... allowing the attacker to perform “active” tasks such as sending keypresses/mouse clicks to Chrome
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
After a few minutes, all web credentials, history, user profiles stored by Chrome will be sent to attackers... Chrolog is an independent tool that extracts user personal data out of the Chrome database... Cookies, Web Data, Login Data, History, and Local State
The Google Chrome extensions are able to steal users’ credentials stored in Chrome and intercept logins of popular banking websites in Brazil... allowing the attacker to perform “active” tasks such as sending keypresses/mouse clicks to Chrome
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
Chronod module – a credential stealer and clipper... and has a clipping functionality that tries to steal BTC, ETH and PIX transfers.
When that happens, it will close the browser and reopen its own instance of Chrome along with index_chronodx2.js being run from the node.exe process... If the user stays connected to the WebSocket C2 server, every six minutes it automatically goes to the targeted Mercado Pago and Mercado Livre pages and performs malicious tasks.
After making an HTTP request to a hardcoded domain... Online.dll retrieves the CnC server specified in the hosts file and performs the beaconing request /aws/newClient.php... Index.js employs two methods of communicating with the attacker: through WebSocket and through HTTP.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
After a few minutes, all web credentials, history, user profiles stored by Chrome will be sent to attackers... Upon visiting any of the above websites, index_chronodx2.js will start collecting the victim’s banking info and send it to the attacker through a set of HTTP commands.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as prior malware that abused browser functions via Chrome DevTools Protocol to enable data theft.
Uses VBScript to execute malicious code.
Banking trojan that collects the username and UID from an infected machine.
Brazil-focused banking trojan delivered via compromised WordPress sites and fake Java installers. It uses a multi-stage chain involving JScript, Python, NodeJS, Delphi DLLs, .NET components, and malicious Chrome extensions to steal Chrome credentials, monitor/intercept banking logins, fingerprint victims, maintain persistence, and exfiltrate financial data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.