logo

Bellerophon could never have imagined. The ChimeraWire trojan boosts website popularity by skillfully pretending to be human

ID: 60c104af-80af-524e-9370-5e297d45eab3

STIX ID: report--60c104af-80af-524e-9370-5e297d45eab3

Feed Name: Dr.Web News

Threat Score
65/100

Date Published: 2025-12-08

Date Updated: 2026-04-27

...
...

Doctor Web analysts describe Trojan.ChimeraWire, a Windows clicker malware that uses chained downloaders, DLL search-order hijacking, UAC bypass and anti-debugging to install a stealthy Chrome-based automation environment; it receives AES-GCM encrypted tasks from C2 over WebSocket to perform search-engine queries, open links and simulate human clicks (and can leverage automated CAPTCHA-solving extensions). The report details two distinct infection chains, persistence via scheduled tasks/registry, described IOCs, and MITRE ATT&CK mappings, noting potential for expanded capabilities beyond click-fraud (form submission, screenshots, data collection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.