Netskope Threat Labs

ChChes

ATP Sandbox Adv. Heuristics

ChChes is a trojan that the menuPass intrusion set appears to have used exclusively, targeting Japanese organizations with it in 2016. Its lack of persistence methods suggests the designers intended it as a first stage tool.

First seen
March 2022
Last seen
October 2026

12 techniques across 6 tactics.

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Win32.Backdoor.ChChes
Win32.Trojan.ChChes