Executive Summary
Chaes is a banking trojan that harvests login credentials and credit card information from Brazilian and Latin American e‑commerce users. It achieves this through browser injection, keylogging, and clipboard monitoring, then exfiltrates the data to remote servers via encrypted channels.
Enhanced Description
Chaes is a sophisticated, multistage information stealer that combines code written in several programming languages into a single threat family. The malware is engineered to harvest sensitive data from victims’ browsers and input devices, capturing login credentials, credit card numbers, and other financial details commonly used for e‑commerce transactions. During infection, Chaes installs lightweight components on the Windows host that inject themselves into legitimate browser processes or run as background services. These components monitor form submissions, intercept keystrokes, and copy clipboard contents to assemble a comprehensive trove of personally identifiable information. Once collected, the data is bundled in a structured payload and transmitted over HTTPS to command‑and‑control servers located primarily in Brazil, aligning with reports that target residents and online shoppers in Latin America. The malware’s modular architecture allows it to update itself with new modules as it propagates, making it resilient against static analysis. Early stages establish persistence through scheduled tasks or auto‑run registry keys, while later phases focus on data exfiltration and potential lateral movement within the victim network using privileged credentials leaked during the credential-stealing process.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence comes from a single external citation, providing a baseline but limited detail on persistence mechanisms and network indicators. Consequently, confidence is moderate; further analysis of artefacts or malware samples would improve accuracy.
Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.(Citation: Cybereason Chaes Nov 2020)