Home/Threat Actor/Chimera (G0114)
Threat Actor

Chimera (G0114)

chimera_china · china · active since 2018

Chimera (canonical CyCraft naming.

MITRE Group G0114.

Fox- IT + NCC Group CUTR "Chimera Under the Radar" tracking) is a People's Republic of China state-aligned cyber-espionage cluster active publicly since 2018, suspected of operating in Chinese state interests with primary operational mission objectives of intelligence collection and industrial espionage targeting Taiwan semiconductor industry intellectual property, operationally consistent with the long-standing Chinese-state-aligned strategic objective of acquiring advanced semiconductor manufacturing capability; one of the most operationally significant Taiwan-focused China-attributed APT clusters in modern cyber-threat- intelligence reporting, operationally distinguished by (1) Taiwan semiconductor industry as signature primary targeting sector, (2) custom Skeleton Key Injector Active Directory authentication-process-patching tooling enabling sustained persistent access through AD authentication memory patching, (3) signature year-long+ dwell-time intrusion campaigns; canonical 2019 "Operation Skeleton Key" CyCraft disclosure documented sustained intrusions against Taiwan semiconductor vendors in Hsinchu Science Park with intellectual-property exfiltration objectives (IC chips, SDKs, IC designs, source code)

January 12, 2021 Fox-IT + NCC Group "Abusing Cloud Services to Fly Under the Radar" disclosure documented operational expansion to European Union semiconductor industry (including Dutch NXP) and EU aviation industry (passenger data theft), 42 of 67 adversarial techniques identical to documented Chimera operations.

signature tradecraft includes Skeleton Key Injector AD authentication patching, Counterfeit Google Chrome Update Cobalt Strike Beacon masquerading, Google Cloud Platform / Appspot / Azure Edge C2 infrastructure abuse for traffic-profile evasion, ChimeRAR custom modified-RAR exfiltration tooling, Winnti backdoor operational adoption, LSASS + NTDS credential-access dual approach, Pass-the-Hash + DLL injection lateral movement, Two-Factor Authentication Interception (CUTR observation), Living-off-the-Land Binaries for white-list circumvention.

UTC+8 timezone operational pattern (CyCraft + Fox-IT/NCC Group independent observation) consistent with mainland China operational basing.

fills the Taiwan- semiconductor-industry-targeting China-attributed APT cell in the curated corpus complementing broader China-attributed APT coverage across ~31 adjacent clusters.

china confidence: high 14 aliases MITRE ATT&CK G0114 ↗

Profile

Chimera (canonical CyCraft naming Chimera.

MITRE ATT&CK Group G0114.

Fox-IT + NCC Group January 2021 tracking referred to in CyCraft analysis as CUTR / "Chimera Under the Radar") is a People's Republic of China state-aligned cyber-espionage cluster active publicly since 2018, suspected of operating in Chinese state interests with primary operational mission objectives of intelligence collection and industrial espionage targeting Taiwan semiconductor industry intellectual property. The cluster is one of the most operationally significant Taiwan-focused China- attributed APT clusters in modern cyber-threat-intelligence reporting and is operationally distinguished from broader China-attributed APT clusters through three signature operational-pattern features: (1) Taiwan semiconductor industry as signature primary targeting sector (operationally consistent with the long-standing Chinese-state-aligned strategic objective of acquiring advanced semiconductor manufacturing capability)

(2) custom Skeleton Key Injector Active Directory authentication-process-patching tooling (operationally enabling sustained persistent access through AD authentication-process memory patching that survives normal user credential rotations)

(3) signature year-long+ dwell-time intrusion campaigns enabling sustained intellectual-property exfiltration operations. Operational phases of the cluster's longitudinal history: (1) OPERATIONAL EMERGENCE AND OPERATION SKELETON KEY ERA (2018-2020). The cluster's operations were first observed during late 2018, with CyCraft documenting earliest tracked operations starting from approximately November-December 2018. Throughout 2019, multiple Taiwan semiconductor industry companies in the Hsinchu Science Park (Taiwan's primary semiconductor industrial cluster in Hsinchu City) were victims of sustained advanced-persistent-threat intrusion operations. CyCraft tracked and disclosed the campaign under the canonical naming "Operation Skeleton Key" with the operational objective characterized as "stealing intelligence, specifically documents about IC chips, software development kits, IC designs, source code, etc." The campaign-naming "Operation Skeleton Key" derives from the cluster's signature custom Skeleton Key Injector tooling. (2) CUTR / EU SEMICONDUCTOR + AVIATION EXPANSION ERA (2020-2021). On January 12, 2021, Fox-IT and NCC Group published "Abusing Cloud Services to Fly Under the Radar" tracking closely-related operations subsequently referred to in CyCraft analysis as CUTR ("Chimera Under the Radar") with 42 of 67 adversarial techniques identical to documented Chimera operations. CUTR operations operationally expanded the cluster's target sets beyond Taiwan semiconductor industry to include European Union semiconductor industry (including Dutch semiconductor company NXP) AND EU aviation industry (passenger data theft from EU airline companies). The CUTR EU-expansion operational pattern was operationally consistent with Chinese-state-aligned industrial-espionage expansion into the EU semiconductor supply chain. (3) CONTINUED OPERATIONS POST-PUBLIC-DISCLOSURE (2021- Present). Following the January 2021 CUTR public disclosure, public reporting on continued Chimera operations has been limited. The cluster's continued operational tempo through 2022-2025 is plausible based on sustained strategic Chinese- state-aligned interest in semiconductor industry intellectual property and continued Chinese-state-aligned industrial- policy priorities.

Signature operational tradecraft includes
  • Skeleton Key Injector Active Directory authentication patching: The cluster's signature custom tooling and most operationally distinctive technical capability. The Skeleton Key technique was originally observed by Dell SecureWorks Counter Threat Unit in 2014. Chimera operationalized and extended the technique with custom tooling incorporating extracted code snippets from Mimikatz and Dumpert. The Chimera Skeleton Key Injector patches AD authentication memory in-place, enabling the attacker to authenticate as any user with a single master password while normal authentication continues to work for legitimate users, operationally minimizing detection probability and enabling persistent access that survives normal user credential rotations.
  • Long dwell-time intrusion operational pattern: CyCraft documented operations where the cluster maintained access to victim environments for periods spanning up to three years. The long-dwell-time pattern is enabled by Skeleton Key Injector AD authentication-patching combined with cloud platform C2 abuse for traffic-profile evasion.
  • Cloud platform C2 infrastructure abuse: Chimera operations consistently abuse legitimate cloud platforms (Google Cloud Platform, Microsoft Appspot, Azure Edge) for command-and-control infrastructure staging, exploiting the legitimate-service traffic profile of major cloud providers to evade network-detection signatures.
  • Counterfeit Google Chrome Update masquerading: signature defense-evasion tradecraft of masquerading Cobalt Strike Beacon as a Google Chrome Update binary. The Counterfeit Chrome Update tradecraft, combined with Google Cloud Platform C2 staging, operationally combines legitimate-service traffic profile with legitimate-update binary masquerading to make attribution difficult for defenders.
  • ChimeRAR exfiltration tooling: CyCraft-named modified RAR archive utility for data exfiltration, old and patched RAR version modified for compressed archival of collected intellectual-property data prior to exfiltration.
  • Winnti backdoor operational adoption: CyCraft documented Chimera operations using the Winnti backdoor, a backdoor historically associated with the broader APT41 / Wicked Panda ecosystem (curated separately as apt41_wickedpanda.yaml). The Winnti adoption is operationally consistent with the CyCraft observation that "China-linked threat actors (e.g., Chimera, BlackTech, APT30) are known to share tools and attack methods with each other, making attribution challenging.".
  • Living-off-the-Land Binaries (LOLBAS) use: signature tradecraft for circumventing white-list-enforcement approaches that some semiconductor vendors employ.
  • Two-Factor Authentication interception: CUTR operations documented Two-Factor Authentication Interception tradecraft (T1111), operationally distinguishable among 2020-era China-attributed clusters and reflective of the cluster's operational sophistication in penetrating defense-in-depth authentication systems.
  • Pass-the-Hash + DLL Injection lateral movement: signature lateral-movement tradecraft enabled by credential access from Mimikatz + Skeleton Key Injector + NTDS dumping.
  • NTDS + LSASS credential access dual approach: signature Chimera credential-access tradecraft combining LSASS Memory dumping (T1003.001) with NTDS dumping (T1003.003) for comprehensive Active Directory credential collection. The cluster fills the Taiwan-semiconductor-industry-targeting China-attributed APT cell in this curated corpus, complementing the broader China-attributed APT coverage across approximately 31+ existing China-attributed clusters (apt1, apt3, apt10, apt17, apt31, apt40, apt41, aoqin_dragon, aquatic_panda, blacktech, cloud_atlas, daggerfly, dark_pink, earth_lusca, emissary_panda, flax_typhoon, gallium, goblin_panda_1937cn, icefog, ke3chang, mirrorface, mustang_panda, naikon, redfoxtrot, redhotel, salt_typhoon, sea_turtle, silk_typhoon, tick_bronze_butler, toddycat, tonto_team, tropic_trooper, volt_typhoon). Chimera is operationally distinct from these adjacent China-attributed clusters through the signature Taiwan-semiconductor primary targeting sector, the signature Skeleton Key Injector tooling, and the signature year-long+ dwell-time intrusion pattern that distinguishes the cluster's intellectual- property-collection-focused operational mission objectives.

Aliases

14
chimerachimera aptchimera chinachimera_aptg0114g-0114cutrchimera under the radarchimera-under-the-radaroperation_skeleton_keyoperation skeleton keyoperation_skeleton_key_2019chimera_chinachimera group

Notable Campaigns

9
2021-presentContinued Operations Post-Public-Disclosure (2021-Present)
2021Fox-IT + NCC Group CUTR Disclosure, EU Semiconductor + Aviation Expansion (January 12, 2021)
2019-presentCounterfeit Google Chrome Update, Cobalt Strike RAT Masquerading (2019-Present)
2019-presentChimeRAR, Modified RAR Exfiltration Tooling (Signature Tradecraft)
2019Operation Skeleton Key, Year-Long Taiwan Semiconductor Industry Campaign (2019)
2018-presentSkeleton Key Injector, Signature Custom Tooling (2018-Present)
2018-presentCloud Platform C2 Infrastructure Abuse, Signature Operational Pattern
2018-presentLong Dwell-Time Intrusion Operational Pattern
2018Chimera Operational Emergence (2018)

Attribution & Reporting

Attributed by
CyCraft TechnologyFox-ITNCC GroupMITRE ATT&CKMandiantCrowdStrikeMicrosoft Threat Intelligence CenterRecorded Future Insikt GroupTrend MicroSymantec / Broadcom Threat Hunter TeamTrellix Advanced Research CenterSecureWorks Counter Threat UnitESETPwC Threat IntelligenceTaiwan TWNCERTDell SecureWorks Counter Threat Unit (historical Skeleton Key research, 2014)
Key reporting
reportCyCraft Technology (Bletchley Chen, Inndy Lin, SHANG-DE Jiang): APT Group Chimera, APT Operation Skeleton Key Targets Taiwan Semiconductor Vendors (April 16, 2020), canonical CyCraft Operation Skeleton Key full disclosure
reportCyCraft Technology: Threat Attribution, Chimera 'Under the Radar' (January 26, 2021), canonical Chimera-CUTR attribution analysis
reportFox-IT + NCC Group: Abusing Cloud Services to Fly Under the Radar (January 12, 2021), canonical Fox-IT+NCC second-vendor CUTR disclosure with EU semiconductor + aviation expansion
reportMITRE ATT&CK Group G0114, Chimera
reportCyCraft HITBLockdown 2020 Conference Presentation: Operation SemiChimera, APT Operation Targets Semiconductor Vendors
reportDell SecureWorks Counter Threat Unit: Skeleton Key Malware Analysis (2014), historical Skeleton Key tradecraft research that operationally informed Chimera tooling development
reportMandiant: China-Attributed Cluster Tracking, Chimera Adjacent Activity
reportCrowdStrike Global Threat Report: China-Attributed Cluster Tracking
reportMicrosoft Threat Intelligence: China-Attributed Cluster Tracking
reportRecorded Future Insikt Group: China State-Aligned Cyber-Espionage Tracking
reportTrend Micro: Taiwan-Targeted Cluster Tracking
reportSymantec / Broadcom Threat Hunter Team: Chimera Operational Analysis
reportTrellix Advanced Research Center: Chimera Continued Tracking
reportSecureWorks Counter Threat Unit: Skeleton Key Tradecraft Research (multiple years)
reportESET: Chimera + China-Attributed Cluster Continued Tracking
reportPwC Threat Intelligence: Chimera Operational Profile
reportTaiwan TWNCERT: National Cybersecurity Coordination on Taiwan-Targeted Operations
reportMalpedia Actor Profile: Chimera

Operational

State sponsor

People's Republic of China state-aligned cyber-espionage cluster, financially-motivated by Chinese-state intelligence- collection and industrial-espionage operational requirements rather than pure financially-motivated cybercrime. CyCraft (the Taiwanese cybersecurity firm that provided the canonical cluster-naming and operational disclosure) characterizes the cluster as "suspected of operating in Chinese state interests" based on (a) targeting patterns operationally aligned with strategic Chinese-state-aligned interests (Taiwan semiconductor industry intellectual-property theft directly aligns with Chinese-state-aligned semiconductor-industry industrial policy and the broader Chinese-state-aligned strategic objective of acquiring advanced semiconductor manufacturing capability)

(b) operator-language artifacts and operational- timezone indicators consistent with mainland China.

(c) UTC+8 timezone operational pattern (CyCraft + Fox-IT/NCC Group independent observation)

(d) operational tradecraft consistency with broader China-attributed APT clusters.

(e) signature targeting of Taiwan (consistent with the broader Chinese-state-aligned strategic operational interest in Taiwan-targeted intelligence collection across the broader Chinese-state-aligned APT ecosystem). The specific Chinese government agency or PLA / MSS unit assignment has not been formally asserted by any government cybersecurity authority. Fox-IT and NCC Group's January 2021 "Abusing Cloud Services to Fly Under the Radar" report independently tracked closely- related activity (referred to in CyCraft analysis as CUTR / "Chimera Under the Radar") with 42 of 67 adversarial techniques identical to CyCraft's documented Chimera operations, and CyCraft assessed "There is a strong probability the threat actor, CUTR, is Chimera as their IoCs, commonly used infra, tools, techniques, and behaviors are all very similar to Chimera." CUTR operations expanded target sets beyond Taiwan semiconductor industry to include European Union semiconductor industry and EU aviation industry, operationally consistent with Chinese-state- aligned industrial-espionage expansion into the EU semi- conductor supply chain. The Dutch semiconductor company NXP breach has been operationally associated with Chimera operations (CUTR European operations). The cluster is one of the most operationally significant Taiwan-focused China- attributed APT clusters in modern cyber-threat-intelligence reporting and operationally distinguishes itself from broader China-attributed clusters through (a) Taiwan semiconductor industry as signature primary targeting sector; (b) custom Skeleton Key Injector Active Directory authentication-process-patching tooling.

(c) signature year- long dwell-time intrusion campaigns enabling sustained intellectual-property exfiltration operations. No formal Chinese government attribution has been asserted by any government cybersecurity authority.

Motivations
cyber_espionage_intelligence_collection, industrial_espionage, semiconductor_intellectual_property_theft, technology_theft, chip_design_data_exfiltration, aviation_passenger_data_collection, long_dwell_time_persistent_intrusion
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SC EXESHARPHOUNDSKELETON KEY INJECTOR
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin