Researchers reported substantial overlap between malware attributed to Chimera and APT19, linking the clusters through shared PE-header anomalies, near-identical code, and common use of Cobalt Strike, Meterpreter, reflective DLL loading, and SMB named-pipe pivoting. Analysis of suspected Chimera samples found multiple related payloads used from 2017 through 2020, including variants that exposed a standard ReflectiveLoader export and others that hid it behind ordinal-only or renamed exports such as execute, while preserving similar persistence, host profiling, and lateral movement behavior.
The broader activity aligns with earlier APT19 operations targeting law and investment firms with phishing lures that exploited CVE-2017-0199, malicious XLSM macros, obfuscated PowerShell, and at least one Cobalt Strike BEACON payload. Separate analysis of an APT19-linked Derusbi backdoor showed service- or registry-based persistence, host reconnaissance, XOR-and-Base64-encoded exfiltration over HTTP/HTTPS, and follow-on DLL loading, while updated OwlProxy samples tied to Chimera added HTTPS listener capability on port 443, a webshell-like endpoint, service persistence, and file-management features to bridge DMZ and internal networks for remote command execution.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
The Chimera/APT19 analysis says the most recent Chimera samples had adopted the same export-hiding modification by August 1, 2020. This change replaced obvious ReflectiveLoader references with ordinal-based or renamed exports such as execute.
Researchers identified three more recent samples from July 2020, including newer 32-bit and 64-bit OwlProxy variants and a dropper they named OwlInstaller. The dropper installed an architecture-appropriate OwlProxy payload as wmipd.dll in system32 and created a wmipd service for persistence.
Another February 2019 OwlProxy sample used HTTPS on port 443 with /topics/ for remote command execution and /topics/pp/ for proxying. The sample used the Windows service name wmipd.
A February 2019 OwlProxy sample used HTTPS on port 443 with /HelpTheme/ for remote command execution and /HelpTheme/pp/ for proxying. It used the Windows service name FastUserSwitchingCompatibility for persistence.
The malware clustering analysis reports newer related samples from 2019–2020 that shared PE-header anomalies, reflective-loading patterns, and high code reuse with older samples. The author assessed them as likely built from a common template with configuration differences such as IP addresses or domains.
FireEye observed a phishing campaign in May and June 2017 targeting at least seven global law and investment firms and attributed it to APT19. Early activity used RTF attachments exploiting CVE-2017-0199, and later activity shifted to macro-enabled Excel documents, including some with an application-whitelisting bypass.
The Chimera/APT19 malware analysis states that related samples identified through YARA hunting span older 2017–2018 periods, indicating the malware family or template was already in use by then. These samples were later compared for shared malformed PE-header traits, code reuse, and reflective-loading behavior.
Lab52 analyzed a recent OwlProxy sample from an Internet-exposed server and reported newer variants exposing HTTPS services on port 443 with /exchangetopicservices/ and /exchangetopicservices/pp/ endpoints. The updated malware also added a webshell-like /px/ endpoint supporting directory listing, file upload, and file download commands.
A technical analysis of a DLL backdoor publicly reported as Derusbi described APT19-linked malware that persisted either as a WinHelpSrv Windows service or a Run key entry, profiled infected hosts, and exfiltrated data over HTTP/HTTPS. The sample contacted infrastructure including 106.185.43.96 and www.microsoft-cache[.]com and was designed to retrieve and execute a secondary DLL payload from C2.
An analyst examined a suspicious DLL with a malformed PE header, published a YARA rule based on that anomaly, and used it to hunt related samples on VirusTotal. The resulting analysis linked Chimera- and APT19-attributed samples through shared PE-header signatures, Cobalt Strike and Meterpreter tradecraft, and roughly 98% code reuse in some pairs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
lab52.io
Open sourcecybergeeks.tech
Open sourcegithub.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.