Also known as: tracked as, RECON, CVE-2025-31324, CVE-2025-32819
Chaya_004 is a Chinese threat actor whose recent campaigns have been uncovered by Darktrace and forensic analysts across multiple jurisdictions. The group exploits zero‑day vulnerabilities in SAP environments (CVE‑2025‑31324 and CVE‑2025‑32819) to gain initial footholds, often complementing these attacks with well‑known CVEs in Citrix, Pulse Secure VPN, FortiGate VPN, Zimbra, Microsoft Exchange, Adobe Reader, and Microsoft Word. After compromising a target, Chaya_004 installs custom backdoors drawn from its diverse malware families—ValleyRAT, Sibot, FatDuke, SUNBURST, Raindrop, TEARDROP—as well as publicly available tools such as Cobalt Strike. It establishes persistence through WMI event subscriptions and altered startup scripts, with an additional layer of obfuscation by running rundll32.exe at boot. To exfiltrate data, the actor uses HTTPS to password‑protected Office 365 archives, sometimes staging stolen files in 7‑Zip archives or embedding ISO images within HTML attachments. Command and Control is achieved via algorithmically generated social media accounts that mimic legitimate environments and by hijacking cloud services (Dropbox, Constant Contact) as covert channels. Residential proxies on Azure Virtual Machines further mask the actor’s operations, while encrypted, multi‑layer C2 traffic often incorporates self‑signed TLS certificates. The organization also demonstrates capabilities to compromise Azure AD by creating privileged service principals, thereby enabling mailbox collection through Microsoft 365 and Exchange Web Services API. Credential dumping tools such as Mimikatz, DCSync, and AdFind are frequently employed, with the actor leveraging stolen tokens for lateral movement across administrative SMB shares. Chaya_004’s tactical repertoire indicates a blend of advanced persistence, privilege escalation, and sophisticated data exfiltration methods—all aimed at maximizing revenue from compromised accounts while remaining covert to avoid detection by modern security tools.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Chaya_004 is a sophisticated Chinese APT that combines zero‑day SAP exploitation with a broad toolkit of remote access trojans and cloud‑based command & control. The actor targets critical infrastructure across the United States, European Union, and Middle Eastern nations, primarily for financial gain through data theft and credential abuse. Its operations exhibit high adaptability—leveraging both legacy CVEs and newly disclosed vulnerabilities—while persisting via WMI event subscriptions and hijacked startup scripts. Chaya_004’s dual emphasis on spearphishing social engineering and cloud services such as Azure, Dropbox, and Constant Contact enables stealthy ingress and exfiltration.
Goals & Targeting
The principal goal of Chaya_004 is financial exploitation through the acquisition, theft, and monetization of privileged credentials and sensitive data. By targeting manufacturing, defense, critical infrastructure, and governmental entities—particularly those within the U.S., EU, Israel, Ukraine and China—the actor seeks high-value assets that can be sold or leveraged for further strategic influence. Their operations prioritize stealthy lateral movement (via SMB shares and Azure AD service principals) to expand access once an initial foothold is established. The ability to pivot from SAP servers to cloud tenancy data illustrates a strategy of maximizing compromised environments while minimizing the number of distinct intrusion attempts.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Chaya_004 operates on a rapid, opportunistic tempo, conducting short‑lived campaigns that span multiple sectors simultaneously. The actor combines spearphishing for initial access with automated exploitation chains that rapidly pivot to cloud or on‑prem infrastructure. Victims typically include manufacturing plants, defense contractors, critical infrastructure operators, and government agencies possessing large volumes of privileged credentials or intellectual property. Campaigns are often short in duration—typically weeks—yet leave residual backdoors, such as ValleyRAT or TEARDROP, that can persist for months if undetected. The actor’s tactical diversity—leveraging both zero‑day CVEs and legacy software vulnerabilities—demonstrates an intent to maintain access across a broad attack surface. Notably, Chaya_004 has repeatedly used Azure-based residential proxies and legitimate cloud services for C2, suggesting a preference for low‑cost, globally available infrastructure that complicates attribution efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple public threat reports, security vendor alerts, and forensic evidence linked to Chaya_004. While the core facts—such as SAP zero-day exploitation, ValleyRAT deployment, and extensive use of Azure-based infrastructure—are well corroborated, details regarding operational tempo, exact victim counts, and attribution strength remain incomplete due to limited open‑source disclosures. Consequently, confidence in the actor’s capabilities and tools is high, but uncertainty persists around specific campaign timelines, full extent of cloud C2 networks, and the precise financial impact of data exfiltration activities.
No campaigns linked yet.
No observed data linked yet.
46
Techniques
54
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics