Infamous Chisel Malware Analysis Report
August 31, 2023 · CISA Advisories · Severity: HIGH
Infamous Chisel–A collection of components associated with Sandworm designed to enable remote access and exfiltrate information from Android phones. Executive Summary Infamous Chisel is a collection of components targeting Android devices. This malware is associated with Sandworm activity. It performs periodic scanning of files and network information for exfiltration. System and application configuration files are exfiltrated from an infected device. Infamous Chisel provides network backdoor access via a Tor (The Onion Router) hidden service and Secure Shell (SSH). Other capabilities include network monitoring, traffic collection, SSH access, network scanning, and SCP file transfer. Overview The UK National Cyber Security Centre (NCSC), the U.S. National Security Agency (NSA), U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. Federal Bureau of Investigation (FBI), New Zealand’s National Cyber Security Centre (NCSC-NZ), the Canadian Centre for Cyber Security – part of the Canada’s Communications Security Establishment (CSE), and Australian Signals Directorate (ASD) are aware that the actor known as Sandworm has used a new mobile malware in a campaign targeting Android devices used by the Ukrainian military. The malware is referred to here as Infamous Chisel. Organizations from the United Kingdom, United States, Australia, Canada, and New Zealand have previously linked the Sandworm actor to the Russian GRU's Main Centre for Special Technologies GTsST. Download the PDF version of this report: PDF, 672 KB For a downloadable copy of IOCs, see: AR23-243A STIX JSON (JSON, 30.31 KB ) AR23-243A STIX XML (XML, 38.17 KB ) Malware Summary Infamous Chisel is a collection of components which enable persistent access to an infected Android device over the Tor network, and which periodically collates and exfiltrates victim information from compromised devices. The information exfiltrated is a...
Key Takeaways
- CISA published a malware analysis report on Infamous Chisel Malware Analysis Report, detailing indicators of compromise and mitigation strategies.
- The malware analysis provides critical IoCs and detection methods for network defenders to identify compromise.
- Organizations should review the CISA report and implement recommended detection signatures to defend against Infamous Chisel Malware Analysis Report.