Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Chaes

Chaes

TLP:CLEAR
Family

AI Analysis

· 10 hours ago

Executive Summary

Chaes is a banking trojan that harvests login credentials and credit card information from Brazilian and Latin American e‑commerce users. It achieves this through browser injection, keylogging, and clipboard monitoring, then exfiltrates the data to remote servers via encrypted channels.

Enhanced Description

Chaes is a sophisticated, multistage information stealer that combines code written in several programming languages into a single threat family. The malware is engineered to harvest sensitive data from victims’ browsers and input devices, capturing login credentials, credit card numbers, and other financial details commonly used for e‑commerce transactions. During infection, Chaes installs lightweight components on the Windows host that inject themselves into legitimate browser processes or run as background services. These components monitor form submissions, intercept keystrokes, and copy clipboard contents to assemble a comprehensive trove of personally identifiable information. Once collected, the data is bundled in a structured payload and transmitted over HTTPS to command‑and‑control servers located primarily in Brazil, aligning with reports that target residents and online shoppers in Latin America. The malware’s modular architecture allows it to update itself with new modules as it propagates, making it resilient against static analysis. Early stages establish persistence through scheduled tasks or auto‑run registry keys, while later phases focus on data exfiltration and potential lateral movement within the victim network using privileged credentials leaked during the credential-stealing process.

Key Capabilities

  • Harvester login credentials from web forms and browsers
  • Collects credit card numbers and other financial information
  • Performs keylogging and clipboard monitoring
  • Injects code into legitimate processes to evade detection
  • Exfiltrates collected data over HTTPS C2 channels

ATT&CK Techniques

T1056
T1552
T1041

Recommended Actions

  • Deploy EDR solutions that flag credential‑harvesting behaviors such as browser injection or form scraping

Suggested Tags

Chaes
InformationStealer
CredentialTheft
CardFraud
Brazil
LatinAmerica
FinancialMalware

Confidence Assessment

The available intelligence comes from a single external citation, providing a baseline but limited detail on persistence mechanisms and network indicators. Consequently, confidence is moderate; further analysis of artefacts or malware samples would improve accuracy.

Description

Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.(Citation: Cybereason Chaes Nov 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.