LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0114: Chimera

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.[1][2]

EnterpriseG0114GroupObject v2.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0114: Chimera describes [Chimera](https://attack.mitre.org/groups/G0114) is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.(Citation: Cycraft Chimera April 2020)(Citation: NCC Group Chimera January 2021)

Executive priority

G0114: Chimera is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0114: Chimera by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0114: Chimera appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Chimera

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

59 rows
DomainIDNameRelationship / procedure
EnterpriseT1574.001DLLSub-technique

Chimera has used side loading to place malicious DLLs in memory.[2]

EnterpriseT1074.002Remote Data StagingSub-technique

Chimera has staged stolen data on designated servers in the target environment.[2]

EnterpriseT1053.005Scheduled TaskSub-technique

Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script schtasks /create /ru "SYSTEM" /tn "update" /tr "cmd /c c:\windows\temp\update.bat" /sc once /f /st and to maintain persistence.[1][2]

EnterpriseT1569.002Service ExecutionSub-technique

Chimera has used PsExec to deploy beacons on compromised systems.[2]

EnterpriseT1041Exfiltration Over C2 Channel

Chimera has used Cobalt Strike C2 beacons for data exfiltration.[2]

EnterpriseT1078Valid Accounts

Chimera has used a valid account to maintain persistence via scheduled task.[1]

EnterpriseT1550.002Pass the HashSub-technique

Chimera has dumped password hashes for use in pass the hash authentication attacks.[2]

EnterpriseT1071.001Web ProtocolsSub-technique

Chimera has used HTTPS for C2 communications.[2]

EnterpriseT1106Native API

Chimera has used direct Windows system calls by leveraging Dumpert.[1]

EnterpriseT1556.001Domain Controller AuthenticationSub-technique

Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential.[1]

EnterpriseT1071.004DNSSub-technique

Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic.[2]

EnterpriseT1482Domain Trust Discovery

Chimera has nltest /domain_trusts to identify domain trust relationships.[2]

EnterpriseT1560.001Archive via UtilitySub-technique

Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts.[1][2]

EnterpriseT1021.006Windows Remote ManagementSub-technique

Chimera has used WinRM for lateral movement.[2]

EnterpriseT1083File and Directory Discovery

Chimera has utilized multiple commands to identify data of interest in file and directory listings.[2]

EnterpriseT1087.002Domain AccountSub-technique

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.[1][2]

EnterpriseT1057Process Discovery

Chimera has used tasklist to enumerate processes.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Chimera has used Windows admin shares to move laterally.[1][2]

EnterpriseT1059.001PowerShellSub-technique

Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features.[1][2]

EnterpriseT1003.003NTDSSub-technique

Chimera has gathered the SYSTEM registry and ntds.dit files from target systems.[1] Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via msadcs.exe "NTDS.dit" -s "SYSTEM" -p RecordedTV_pdmp.txt --users-csv RecordedTV_users.csv and used ntdsutil to copy the Active Directory database.[2]

EnterpriseT1074.001Local Data StagingSub-technique

Chimera has staged stolen data locally on compromised hosts.[2]

EnterpriseT1213.002SharepointSub-technique

Chimera has collected documents from the victim's SharePoint.[2]

EnterpriseT1135Network Share Discovery

Chimera has used net share and net view to identify network shares of interest.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe.[1]

EnterpriseT1570Lateral Tool Transfer

Chimera has copied tools between compromised hosts using SMB.[2]

EnterpriseT1007System Service Discovery

Chimera has used net start and net use for system service discovery.[2]

EnterpriseT1027.010Command ObfuscationSub-technique

Chimera has encoded PowerShell commands.[1]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Chimera has cleared event logs on compromised hosts.[2]

EnterpriseT1016System Network Configuration Discovery

Chimera has used ipconfig, Ping, and tracert to enumerate the IP address and network environment and settings of the local host.[2]

EnterpriseT1046Network Service Discovery

Chimera has used the get -b -e -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.[2]

EnterpriseT1033System Owner/User Discovery

Chimera has used the quser command to show currently logged on users.[2]

EnterpriseT1087.001Local AccountSub-technique

Chimera has used net user for account discovery.[2]

EnterpriseT1572Protocol Tunneling

Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS.[2]

EnterpriseT1078.002Domain AccountsSub-technique

Chimera has used compromised domain accounts to gain access to the target environment.[2]

EnterpriseT1069.001Local GroupsSub-technique

Chimera has used net localgroup administrators to identify accounts with local administrative rights.[2]

EnterpriseT1124System Time Discovery

Chimera has used time /t and net time \\ip/hostname for system time discovery.[2]

EnterpriseT1201Password Policy Discovery

Chimera has used the NtdsAudit utility to collect information related to accounts and passwords.[2]

EnterpriseT1049System Network Connections Discovery

Chimera has used netstat -ano | findstr EST to discover network connections.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts.[2]

EnterpriseT1070.004File DeletionSub-technique

Chimera has performed file deletion to evade detection.[1]

EnterpriseT1110.003Password SprayingSub-technique

Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts.[2]

EnterpriseT1114.001Local Email CollectionSub-technique

Chimera has harvested data from victim's e-mail including through execution of wmic /node: process call create "cmd /c copy c:\Users\\\backup.pst c:\windows\temp\backup.pst" copy "i:\\\My Documents\.pst" copy.[2]

EnterpriseT1039Data from Network Shared Drive

Chimera has collected data of interest from network shares.[2]

EnterpriseT1119Automated Collection

Chimera has used custom DLLs for continuous retrieval of data from memory.[2]

EnterpriseT1133External Remote Services

Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services.[1][2]

EnterpriseT1110.004Credential StuffingSub-technique

Chimera has used credential stuffing against victim's remote services to obtain valid accounts.[2]

EnterpriseT1680Local Storage Discovery

Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information.[2]

EnterpriseT1114.002Remote Email CollectionSub-technique

Chimera has harvested data from remote mailboxes including through execution of \\\c$\Users\\AppData\Local\Microsoft\Outlook*.ost.[2]

EnterpriseT1012Query Registry

Chimera has queried Registry keys using reg query \\\HKU\\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\\HKU\\Software\Microsoft\Windows\CurrentVersion\Internet Settings.[2]

EnterpriseT1588.002ToolSub-technique

Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.[1][2]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Chimera has exfiltrated stolen data to OneDrive accounts.[2]

EnterpriseT1070.006TimestompSub-technique

Chimera has used a Windows version of the Linux touch command to modify the date and time stamp on DLLs.[2]

EnterpriseT1018Remote System Discovery

Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment.[2]

EnterpriseT1589.001CredentialsSub-technique

Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks.[2]

EnterpriseT1047Windows Management Instrumentation

Chimera has used WMIC to execute remote commands.[1][2]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Chimera has used RDP to access targeted systems.[1]

EnterpriseT1111Multi-Factor Authentication Interception

Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS.[2]

EnterpriseT1217Browser Information Discovery

Chimera has used type \\\c$\Users\\Favorites\Links\Bookmarks bar\Imported From IE\*citrix* for bookmark discovery.[2]

EnterpriseT1105Ingress Tool Transfer

Chimera has remotely copied tools and malware onto targeted systems.[1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.2
Created
Modified
Raw hash
046ae740b911e9ec...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.2Current bundle046ae740b911…
19.12.2Older bundleeb158edec1e6…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Cycraft Chimera April 2020

    Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..

    Open source URL
  2. [2]
    NCC Group Chimera January 2021

    Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.

    Open source URL
  3. [3]
    Chimera

    (Citation: NCC Group Chimera January 2021)

  4. [4]
    mitre-attackG0114
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.