Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware CHIMNEYSWEEP

CHIMNEYSWEEP

TLP:CLEAR
Family

AI Analysis

· 7 hours ago

Executive Summary

CHIMNEYSWEEP is a long‑lived Windows backdoor used in targeted campaigns against Farsi and Arabic speaking entities. It establishes persistence, receives commands from remote C&C servers, and can download further malware such as ROADSWEEP ransomware. Organizations should monitor for anomalous outbound traffic to known malicious domains and block the malware’s installation mechanisms.

Enhanced Description

CHIMNEYSWEEP is a stealthy Windows backdoor that first appeared in the late‑2010s as part of a broader state‑level campaign known internally as HomeLand Justice. It was deployed contemporaneously with the ROADSWEEP ransomware module and has been observed targeting Persian/Farsi and Arabic speaking organizations since at least 2012, indicating an early focus on the Middle East and South Asia regions. The malware is designed for long‑term persistence and command execution. It installs itself as a legitimate‑looking service or background process and registers persistence mechanisms such as scheduled tasks or registry run keys, allowing it to survive reboots and antivirus cleanup attempts. CHIMNEYSWEEP communicates with compromised hosts over HTTP/HTTPS and custom binary protocols directed at underground C&C servers. Beyond basic remote control, the backdoor can download auxiliary payloads—often additional ransomware, credential harvesters, or tools for lateral movement—and execute them on a victim system. It also logs keystrokes, scrapes local credentials from roaming profiles, and exfiltrates stolen data via encrypted channels to mitigate detection. Defensive researchers have identified the backdoor’s signatures in a variety of corporate and governmental environments, pointing to its persistence as a key component for attackers who aim to establish a foothold before launching more destructive payloads like ROADSWEEP. The continued use of this tool over many years underscores the challenges of tracking sophisticated threat actors that evolve their tooling while maintaining operational security.

Key Capabilities

  • Establishes persistence via scheduled tasks or registry run keys
  • Provides remote command execution through HTTP/HTTPS channels
  • Downloads additional payloads (e.g., ransomware, credential stealers)
  • Exfiltrates stolen credentials and sensitive data over encrypted connections
  • Implements stealth techniques to avoid detection by standard AV products

ATT&CK Techniques

T1059
T1071
T1105
T1086

Recommended Actions

  • Deploy an endpoint detection & response solution that monitors for unfamiliar persistent services or scheduled tasks
  • Block outbound traffic to known command‑and‑control IPs and domains associated with CHIMNEYSWEEP

Suggested Tags

Backdoor
TargetedAttacker
Farsi
Arabic
ROADSWEEP
HomelandJustice

Confidence Assessment

The information is derived from limited published reports; technical details about the malware’s internal architecture, cryptographic methods, and complete threat actor attribution remain undefined. Consequently, confidence in specific behavioral claims is moderate but not exhaustive.

Description

CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target Farsi and Arabic speakers since at least 2012.(Citation: Mandiant ROADSWEEP August 2022)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.