Executive Summary
CHIMNEYSWEEP is a long‑lived Windows backdoor used in targeted campaigns against Farsi and Arabic speaking entities. It establishes persistence, receives commands from remote C&C servers, and can download further malware such as ROADSWEEP ransomware. Organizations should monitor for anomalous outbound traffic to known malicious domains and block the malware’s installation mechanisms.
Enhanced Description
CHIMNEYSWEEP is a stealthy Windows backdoor that first appeared in the late‑2010s as part of a broader state‑level campaign known internally as HomeLand Justice. It was deployed contemporaneously with the ROADSWEEP ransomware module and has been observed targeting Persian/Farsi and Arabic speaking organizations since at least 2012, indicating an early focus on the Middle East and South Asia regions. The malware is designed for long‑term persistence and command execution. It installs itself as a legitimate‑looking service or background process and registers persistence mechanisms such as scheduled tasks or registry run keys, allowing it to survive reboots and antivirus cleanup attempts. CHIMNEYSWEEP communicates with compromised hosts over HTTP/HTTPS and custom binary protocols directed at underground C&C servers. Beyond basic remote control, the backdoor can download auxiliary payloads—often additional ransomware, credential harvesters, or tools for lateral movement—and execute them on a victim system. It also logs keystrokes, scrapes local credentials from roaming profiles, and exfiltrates stolen data via encrypted channels to mitigate detection. Defensive researchers have identified the backdoor’s signatures in a variety of corporate and governmental environments, pointing to its persistence as a key component for attackers who aim to establish a foothold before launching more destructive payloads like ROADSWEEP. The continued use of this tool over many years underscores the challenges of tracking sophisticated threat actors that evolve their tooling while maintaining operational security.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information is derived from limited published reports; technical details about the malware’s internal architecture, cryptographic methods, and complete threat actor attribution remain undefined. Consequently, confidence in specific behavioral claims is moderate but not exhaustive.
CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target Farsi and Arabic speakers since at least 2012.(Citation: Mandiant ROADSWEEP August 2022)