Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Chaya_004

Also known as: tracked as, RECON, CVE-2025-31324, CVE-2025-32819

Description

Chaya_004 is a Chinese threat actor whose recent campaigns have been uncovered by Darktrace and forensic analysts across multiple jurisdictions. The group exploits zero‑day vulnerabilities in SAP environments (CVE‑2025‑31324 and CVE‑2025‑32819) to gain initial footholds, often complementing these attacks with well‑known CVEs in Citrix, Pulse Secure VPN, FortiGate VPN, Zimbra, Microsoft Exchange, Adobe Reader, and Microsoft Word. After compromising a target, Chaya_004 installs custom backdoors drawn from its diverse malware families—ValleyRAT, Sibot, FatDuke, SUNBURST, Raindrop, TEARDROP—as well as publicly available tools such as Cobalt Strike. It establishes persistence through WMI event subscriptions and altered startup scripts, with an additional layer of obfuscation by running rundll32.exe at boot. To exfiltrate data, the actor uses HTTPS to password‑protected Office 365 archives, sometimes staging stolen files in 7‑Zip archives or embedding ISO images within HTML attachments. Command and Control is achieved via algorithmically generated social media accounts that mimic legitimate environments and by hijacking cloud services (Dropbox, Constant Contact) as covert channels. Residential proxies on Azure Virtual Machines further mask the actor’s operations, while encrypted, multi‑layer C2 traffic often incorporates self‑signed TLS certificates. The organization also demonstrates capabilities to compromise Azure AD by creating privileged service principals, thereby enabling mailbox collection through Microsoft 365 and Exchange Web Services API. Credential dumping tools such as Mimikatz, DCSync, and AdFind are frequently employed, with the actor leveraging stolen tokens for lateral movement across administrative SMB shares. Chaya_004’s tactical repertoire indicates a blend of advanced persistence, privilege escalation, and sophisticated data exfiltration methods—all aimed at maximizing revenue from compromised accounts while remaining covert to avoid detection by modern security tools.

Goals & Targeting

Targeted Sectors

Manufacturing
Government
Defense
Think tank
Energy
Financial services
Healthcare
Education
Non profit
Transportation
Aviation
Utilities
Critical infrastructure
Chemical
Media
Mining

Targeted Countries / Regions

US
GB
CN
RU
FR
TR
IQ
UA
RO
NL
IN
BR
KP

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 1 day ago

Executive Summary

Chaya_004 is a sophisticated Chinese APT that combines zero‑day SAP exploitation with a broad toolkit of remote access trojans and cloud‑based command & control. The actor targets critical infrastructure across the United States, European Union, and Middle Eastern nations, primarily for financial gain through data theft and credential abuse. Its operations exhibit high adaptability—leveraging both legacy CVEs and newly disclosed vulnerabilities—while persisting via WMI event subscriptions and hijacked startup scripts. Chaya_004’s dual emphasis on spearphishing social engineering and cloud services such as Azure, Dropbox, and Constant Contact enables stealthy ingress and exfiltration.

Goals & Targeting

The principal goal of Chaya_004 is financial exploitation through the acquisition, theft, and monetization of privileged credentials and sensitive data. By targeting manufacturing, defense, critical infrastructure, and governmental entities—particularly those within the U.S., EU, Israel, Ukraine and China—the actor seeks high-value assets that can be sold or leveraged for further strategic influence. Their operations prioritize stealthy lateral movement (via SMB shares and Azure AD service principals) to expand access once an initial foothold is established. The ability to pivot from SAP servers to cloud tenancy data illustrates a strategy of maximizing compromised environments while minimizing the number of distinct intrusion attempts.

Enhanced Description

Key Capabilities

  • Exploit zero‑day vulnerabilities in SAP components (CVE‑2025‑31324, CVE‑2025‑32819)
  • Deploy and use ValleyRAT remote access trojan

MITRE ATT&CK Tactics

Command and Control
Privilege Escalation
Persistence
Credential Access
Defense Evasion
Exfiltration
Initial Access
Lateral Movement

ATT&CK Techniques

T1001
T1003.004
T1005
T1037
T1047
T1059
T1059.001
T1059.005
T1068
T1083
T1087
T1098
T1102
T1110
T1114
T1133
T1136
T1140
T1190
T1203
T1546
T1546.007
T1547
T1548
T1555
T1560
T1568
T1573
T1583
T1584
T1585
T1586
T1587
T1588.001
T1595
T1606
T1651
T1685
T1686

Software / Tooling

ValleyRAT
Sibot
FatDuke
MiniDuke
RegDuke
PolyglotDuke
Raindrop
TEARDROP
SUNBURST
SUNSPOT
Cobalt Strike
HAMMERTOSS
Tor Hidden Service
SUNSHUTTLE
Nobelium
PowerDuke
WellMess
GoldFinder
AADInternals
meek
Mimikatz
SDelete
AdFind
Phishing Kit
COZYDUKE
Web Shell
PowerShell
LockBit
BianLian
Nexus
RansomEXX
Ghost RAT
SuperShell
Gadget
DCSync

Campaigns & Victims

Chaya_004 operates on a rapid, opportunistic tempo, conducting short‑lived campaigns that span multiple sectors simultaneously. The actor combines spearphishing for initial access with automated exploitation chains that rapidly pivot to cloud or on‑prem infrastructure. Victims typically include manufacturing plants, defense contractors, critical infrastructure operators, and government agencies possessing large volumes of privileged credentials or intellectual property. Campaigns are often short in duration—typically weeks—yet leave residual backdoors, such as ValleyRAT or TEARDROP, that can persist for months if undetected. The actor’s tactical diversity—leveraging both zero‑day CVEs and legacy software vulnerabilities—demonstrates an intent to maintain access across a broad attack surface. Notably, Chaya_004 has repeatedly used Azure-based residential proxies and legitimate cloud services for C2, suggesting a preference for low‑cost, globally available infrastructure that complicates attribution efforts.

IOC Patterns

  • IPv4 address
  • domain name
  • file path/executable
  • hash SHA-256
  • email address/identifier
  • CVE identifier

Recommended Actions

  • Patch SAP components to mitigate CVE-2025-31324 and CVE-2025-32819 immediately
  • Monitor for ValleyRAT signatures and anomalous backdoor activity across endpoints
  • Investigate unauthorized Azure AD service principal creation or privileged account modifications
  • Detect and block WMI event subscription registrations used for persistence
  • Audit the use of Dropbox, Constant Contact, and other cloud services for potential data exfiltration channels
  • Identify newly created social media accounts linked to malicious actors and monitor their outbound traffic
  • Inspect OWA servers for password‑protected archives and staged files
  • Segment the network to restrict access from residential proxy IP ranges, especially Azure VMs
  • Enable and audit Purview Audit logs to detect tampering or disabling attempts
  • Validate mutual TLS certificates; block traffic using self‑signed certificates not issued by trusted authorities
  • Detect encrypted, multi‑layer HTTPS outbound traffic directed at OWA archives as a potential exfiltration vector
  • Patch known CVEs in Citrix, Pulse Secure VPN, FortiGate VPN, Zimbra, Exchange, Microsoft Word, and Adobe Reader
  • Enforce MFA on all privileged accounts; monitor for unauthorized token usage or stolen Kerberos tickets
  • Deploy email security gateways to scan attachments/URLs and implement safe browsing for spearphishing mitigation
  • Block outbound traffic from legitimate mailing services (e.g., Constant Contact) when used in phishing campaigns
  • Detect anomalous creation/use of Tor hidden services that forward RDP/SMB traffic
  • Audit SMB account privileges routinely; monitor lateral movement across SMB shares

Suggested Tags

Chinese threat actor
Zero-day exploitation
SAP vulnerability
ValleyRAT
Darktrace detection
APT29
Chaya_004
SolarWinds
SVR
CVE-2025-31324
CVE-2025-32819
AzureAD
TwitterC2
DropboxC2
CredentialDumping
AccountHijacking
SolarWinds Compromise
SUNBURST
TEARDROP
Cobalt Strike
Tor hidden service
WMI persistence
Spearphishing
Credential theft
Privilege escalation
Self‑signed certificates
Persistent backdoor
Sunshuttle
Nobelium
PowerDuke

Confidence Assessment

The analysis is based on multiple public threat reports, security vendor alerts, and forensic evidence linked to Chaya_004. While the core facts—such as SAP zero-day exploitation, ValleyRAT deployment, and extensive use of Azure-based infrastructure—are well corroborated, details regarding operational tempo, exact victim counts, and attribution strength remain incomplete due to limited open‑source disclosures. Consequently, confidence in the actor’s capabilities and tools is high, but uncertainty persists around specific campaign timelines, full extent of cloud C2 networks, and the precise financial impact of data exfiltration activities.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.infosecurity-magazine.com — Cited by web research for: CVE-2025-31324
  2. risky.biz — Cited by web research for: CVE-2025-32819
  3. attack.mitre.org — Cited by web research for: T1548
  4. www.ibm.com — Cited by web research for: LockBit
  5. www.forescout.com — Cited by web research for: GitHub
  6. https://www.gov.uk/government/news/global-campaign-malign-activity-russian-intelligence — Cited by AI analysis.
  7. https://secure.dhs.gov/2021/ap29-report — Cited by AI analysis.
  8. https://sec.report/fireeye_solarwinds_compromise_analysis — Cited by AI analysis.
  9. https://www.pwc.com/gx/en/services/research-and-insights/society/wellmess-vaccine.html — Cited by AI analysis.

Intel Summary

46

Techniques

54

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Backdoor / C2
SAP
NetWeaver
CVE-2025-31324
APT
Chinese threat actor
Cyber espionage
Zero-day exploitation
SAP vulnerability
ValleyRAT
Darktrace detection
APT29
Chaya_004
SolarWinds
SVR
CVE-2025-32819
AzureAD
TwitterC2
DropboxC2
CredentialDumping
AccountHijacking
SolarWinds Compromise
SUNBURST
TEARDROP
Cobalt Strike
Tor hidden service
WMI persistence
Spearphishing
Credential theft
Privilege escalation
Self‑signed certificates
Persistent backdoor
Sunshuttle
Nobelium
PowerDuke

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.