A long-running cyberespionage campaign dubbed ChessMaster targeted organizations in Japan across academia, media, technology, managed service providers, pharmaceuticals, and government, using spear-phishing emails and decoy documents to gain initial access. Researchers linked the activity to the China-associated APT10/menuPass cluster based on overlapping targeting, shared infrastructure, malware tradecraft, packers, and reuse of known tooling. Early intrusions delivered malware including ChChes, PlugX, Poison Ivy, RedLeaves, malicious .LNK files, PowerShell-based loaders, and credential-dumping utilities, with some lures spoofing trusted entities and using topical political themes to entice victims.
The campaign evolved from first-stage footholds to more selective post-compromise operations, adding the ANEL backdoor and the open-source post-exploitation framework Koadic while refining loaders, DLL side-loading chains, and command-and-control methods. Delivery techniques included malicious Office documents exploiting CVE-2017-8759 and CVE-2017-11882, as well as abuse of Office features such as DDEAUTO, Frameset, and Link Auto Update. Technical reporting described ChChes as a sophisticated backdoor that could operate filelessly, profile infected hosts, communicate with C2 servers through HTTP Cookie headers with encrypted data, and stage follow-on payloads, underscoring a sustained and adaptive espionage effort against Japanese targets.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
Trend Micro published follow-on research showing ChessMaster had evolved from using ChChes and RedLeaves to newer ANEL variants, additional credential-theft tools, and DLL side-loading techniques.
Trend Micro reported that it initially discovered the ANEL backdoor in September 2017 as part of the evolving ChessMaster campaign.
Trend Micro published research on ChessMaster, describing a Japan-focused espionage campaign using ChChes, TinyX, RedLeaves, malicious LNK files, and PowerShell, and highlighting overlaps with APT10/menuPass.
Trend Micro said it discovered the ChessMaster cyberespionage campaign in July 2017 while monitoring attacks targeting organizations in Japan.
Palo Alto Networks publicly reported with high confidence that the 2016 attacks against Japanese organizations were conducted by menuPass/APT10 and linked ChChes to the group through infrastructure and malware overlaps.
JPCERT/CC published a report on ChChes describing malware that communicates with its command-and-control server via HTTP Cookie headers.
A ChChes sample analyzed by Unit 42 carried a compile timestamp of 2016-11-24 01:31:37 UTC, providing a concrete anchor for malware development during the campaign.
Two days after the 2016 U.S. election, the attackers used the subject line "[UNCLASSIFIED] The impact of Trump’s victory to Japan" in a spear-phishing lure sent during the campaign.
From September through November 2016, a menuPass/APT10 campaign targeted Japanese academics, Japanese pharmaceutical organizations, and a U.S.-based subsidiary of a Japanese manufacturer using spear-phishing emails.
HackingTeam was compromised in July 2015, and leaked internal data included certificates later used to digitally sign ChChes samples targeting Japanese organizations.
Palo Alto Networks said menuPass/APT10 had targeted Japanese organizations since at least 2014, marking an established focus on Japan before the later ChessMaster reporting.
Trend Micro reported that ChessMaster used the Koadic post-exploitation framework to collect environment information and selectively download a base64-encrypted ANEL payload only to systems deemed of interest.
A later phase of ChessMaster adopted the ANEL backdoor and delivered it through malicious Office documents exploiting CVE-2017-8759 and CVE-2017-11882, while also abusing DDEAUTO, Frameset, and Link Auto Update.
Trend Micro said a RedLeaves variant named himawari emerged in April and could evade YARA rules released at that time, indicating ongoing tool evolution in the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 89 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
blog.trendmicro.com
Open sourceblog.trendmicro.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcejpcert.or.jp
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.