Chimera is a Windows ransomware family known for targeted email-based distribution against small companies. It encrypts files on available disks and appends a .crypt-style extension, then presents an HTML ransom note in English or German, including full-screen display through Internet Explorer. Chimera became notable for early use of leak-style extortion threats, claiming that stolen files and credentials would be published if payment was not made; however, examined samples indicated that this exfiltration threat was not actually implemented in those builds.
The malware has been documented as a multi-stage loader chain consisting of a packed .NET stub, an intermediate loader, and a core payload. The stub decrypts and launches the next stage using RunPE-style or manual-mapping techniques, while the core component performs host identification, encryption, ransom-note handling, and network communications. Chimera generates victim-specific identifiers from host characteristics, collects basic system information, and uses asymmetric cryptography to protect per-file symmetric encryption keys. It processes files in chunks and communicates over the Bitmessage peer-to-peer protocol rather than relying solely on conventional centralized command-and-control infrastructure.
Separately from the ransomware family, Chimera is also tracked as an intrusion set associated with enterprise post-compromise activity. That activity includes credential abuse, password-hash dumping for pass-the-hash, bookmark and email collection, network-share discovery, domain-trust discovery, network scanning, scheduled-task persistence, timestomping, HTTPS and DNS-encapsulated command-and-control, and exfiltration to attacker-controlled channels and cloud storage. Those intrusion-set behaviors should not be conflated with the original ransomware family unless specifically distinguished in analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files… actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe … has used legitimate names and locations for files to evade defenses.”
"vba_macro.exe deletes itself..."; "AcidPour includes a self-delete function where the malware deletes itself from disk after execution"; "APT29 has used SDelete to remove artifacts"; "Operation Wocao... overwriting a file... and then deleting the overwritten file"
“performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities… has used CrackMapExec and a custom port scanner… used a malware variant… to conduct port scans… used nmap… masscan… zmap and zgrab… to scan for open ports/vulnerable services.”
"...used tasklist to enumerate processes..."; "...used the ps command to list processes..."; "...calling CreateToolhelp32Snapshot... to enumerate the running processes..."
The victim ID is generated basing on hardware – also, some other information about the local machine is collected: computer name and external IP
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as a ransomware operation that has run an affiliate program.
Publicly accessible antivirus-evasion framework referenced as contributing to the proliferation of evasive malware.
Ransomware family that encrypts files and appends .crypt or a pattern including four random tokens.
Referenced only as an example of prior ransomware using BitMessage to communicate with victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.