Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Chamelgang

Also known as: CamoFei

Description

In Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company. The investigation revealed that the company's network had been compromised by an unknown group for the purpose of data theft. They gave the group the name ChamelGang (from the word "chameleon"), because the group disguised its malware and network infrastructure under legitimate services of Microsoft, TrendMicro, McAfee, IBM, and Google.

Goals & Targeting

Targeted Sectors

Energy

AI Analysis

· 1 week ago

Executive Summary

Chamelgang, also known as CamoFei, is a sophisticated cyber threat actor targeting the energy sector primarily for data theft. Disguising their activities under legitimate services of major companies like Microsoft and TrendMicro, they employ advanced tactics to avoid detection, making them a significant threat to critical infrastructure.

Goals & Targeting

Chamelgang's primary goal appears to be data theft, targeting the energy sector, which holds sensitive information and strategic infrastructure. Their focus on this sector may stem from either financial motives or espionage aims, though their broader targets remain unclear outside of the energy industry.

Enhanced Description

Chamelgang emerged in Q2 2021 when an incident response team investigating a compromised energy company identified the group. The name 'ChamelGang' reflects their ability to blend into legitimate services, using disguise techniques for both malware and network infrastructure. This tactic allows them to逃避 detection while conducting data theft activities. Their operations suggest a high level of technical proficiency, likely tied to advanced persistent threat (APT) groups with significant resources.

Key Capabilities

  • Advanced data exfiltration tactics
  • Living off the land (LOLBin usage)
  • sophisticated disguise techniques to mimic legitimate services
  • Network persistence mechanisms

MITRE ATT&CK Tactics

Collection
Exfiltration
Defense Evasion

ATT&CK Techniques

T1059.003
T1078.004

Software / Tooling

Custom malware disguised as legitimate services
PowerShell scripting for command and control

Campaigns & Victims

Chamelgang has been observed in a single campaign during Q2 2021, focusing on data theft from energy companies. Their operations suggest they may target similar industries with slow-moving campaigns to avoid detection. Monitoring of their activity is essential due to their sophisticated techniques.

IOC Patterns

  • Use of legitimate-looking domain names for C2
  • Scheduled task creation for persistence
  • Abnormal network traffic mimicking normal service updates

Recommended Actions

  • Implement network segmentation to isolate critical systems
  • Monitor for LOLBin and unusual PowerShell activity
  • Ensure regular patching of systems
  • Enforce multi-factor authentication (MFA) for sensitive accounts

Suggested Tags

APT
espionage
cyber espionage
energy sector

Confidence Assessment

Confidence in Chamelgang's details is moderate due to limited public data, particularly regarding their long-term goals and specific ties to nation-states or other groups. Further analysis of their tools and TTPs could enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Data Exfiltration
APT
espionage
cyber espionage
energy sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.