SYMBOLCOMMON_NAMEaka. SYNONYMS
win.chaperone (Back to overview)

Chaperone

aka: Taj Mahal
VTCollection    

According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky Lab in the autumn of 2018. This full-blown spying framework consists of two packages named Tokyo and Yokohama. It includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers, and even its own file indexer for the victim’s machine. We discovered up to 80 malicious modules stored in its encrypted Virtual File System, one of the highest numbers of plugins they have ever seen for an APT toolset.

References
2020-01-24 ⋅ Github (TheEnergyStory) ⋅ R136a1
Project TajMahal IOCs and Registry Data Decrypter
Chaperone
2019-08-01 ⋅ Kaspersky Labs ⋅ GReAT
APT trends report Q2 2019
ZooPark magecart POWERSTATS Chaperone COMpfun EternalPetya FinFisher RAT HawkEye Keylogger HOPLIGHT Microcin NjRAT Olympic Destroyer PLEAD RokRAT Triton Zebrocy
2019-04-10 ⋅ Kaspersky Labs ⋅ AMR, GReAT
Project TajMahal – a sophisticated new APT framework
Chaperone
Yara Rules
[TLP:WHITE] win_chaperone_auto (20260917 | Detects win.chaperone.)
rule win_chaperone_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.chaperone."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chaperone"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488905???????? 488d9424a8010000 488b8c24a0010000 ff15???????? 488905???????? }
            // n = 5, score = 100
            //   488905????????       |                     
            //   488d9424a8010000     | cmp                 ecx, ebx
            //   488b8c24a0010000     | jge                 0x129b
            //   ff15????????         |                     
            //   488905????????       |                     

        $sequence_1 = { c6442455ec c6442456ef c6442457d0 c644245820 c644245902 c644245a15 }
            // n = 6, score = 100
            //   c6442455ec           | dec                 eax
            //   c6442456ef           | add                 eax, 1
            //   c6442457d0           | dec                 eax
            //   c644245820           | mov                 dword ptr [esp + 0x968], eax
            //   c644245902           | jmp                 0x1e36
            //   c644245a15           | dec                 eax

        $sequence_2 = { 4c8d442460 33d2 b901001f00 ff15???????? 4889442420 48837c242000 }
            // n = 6, score = 100
            //   4c8d442460           | lea                 eax, [esp + 0x280]
            //   33d2                 | dec                 eax
            //   b901001f00           | mov                 dword ptr [esp + 0x20], eax
            //   ff15????????         |                     
            //   4889442420           | dec                 esp
            //   48837c242000         | mov                 ecx, dword ptr [esp + 0xc00]

        $sequence_3 = { 4155 4883ec20 4863d9 4c8be3 49c1fc05 4c8d2de6980100 83e31f }
            // n = 7, score = 100
            //   4155                 | lea                 edx, [0x1944b]
            //   4883ec20             | and                 ecx, 0x1f
            //   4863d9               | dec                 eax
            //   4c8be3               | sar                 eax, 5
            //   49c1fc05             | dec                 eax
            //   4c8d2de6980100       | imul                ecx, ecx, 0x58
            //   83e31f               | dec                 eax

        $sequence_4 = { 4889442420 48837c242000 7507 33c0 e9???????? 488d7c2430 488d35cc4a0100 }
            // n = 7, score = 100
            //   4889442420           | cmp                 dword ptr [esp + 0x330], 0
            //   48837c242000         | jne                 0x17a
            //   7507                 | dec                 eax
            //   33c0                 | lea                 ecx, [esp + 0x44b0]
            //   e9????????           |                     
            //   488d7c2430           | dec                 eax
            //   488d35cc4a0100       | test                eax, eax

        $sequence_5 = { 837c243000 740a 83bc24a00700001f 7545 488d442434 4889442428 8b8424a0070000 }
            // n = 7, score = 100
            //   837c243000           | mov                 ecx, 0x26
            //   740a                 | rep movsb           byte ptr es:[edi], byte ptr [esi]
            //   83bc24a00700001f     | dec                 eax
            //   7545                 | lea                 edi, [esp + 0x2b0]
            //   488d442434           | mov                 dword ptr [esp + 0x1900], 0x1268
            //   4889442428           | mov                 eax, dword ptr [esp + 0x1900]
            //   8b8424a0070000       | neg                 eax

        $sequence_6 = { 488b8c2450010000 ff15???????? 4533c9 4533c0 ba01000000 488b8c2450010000 }
            // n = 6, score = 100
            //   488b8c2450010000     | neg                 eax
            //   ff15????????         |                     
            //   4533c9               | mov                 dword ptr [esp + 0x1900], eax
            //   4533c0               | inc                 ecx
            //   ba01000000           | mov                 ecx, 2
            //   488b8c2450010000     | inc                 ebp

        $sequence_7 = { 0fb700 83f822 750d 33c9 488b842480020000 668908 4883bc24a803000000 }
            // n = 7, score = 100
            //   0fb700               | add                 al, 0
            //   83f822               | add                 byte ptr [ecx], al
            //   750d                 | add                 byte ptr [eax], al
            //   33c9                 | add                 byte ptr [eax - 0x75], cl
            //   488b842480020000     | mov                 word ptr [eax + ecx*4], fs
            //   668908               | add                 al, 0
            //   4883bc24a803000000     | add    byte ptr [eax - 0x75], cl

        $sequence_8 = { 4889442440 48837c2440ff 7412 488b4c2440 ff15???????? b801000000 eb02 }
            // n = 7, score = 100
            //   4889442440           | dec                 eax
            //   48837c2440ff         | lea                 edx, [esp + 0x4710]
            //   7412                 | dec                 eax
            //   488b4c2440           | lea                 ecx, [esp + 0x42a0]
            //   ff15????????         |                     
            //   b801000000           | test                eax, eax
            //   eb02                 | jne                 0x6fc

        $sequence_9 = { 4885c0 0f8473010000 488bc8 e8???????? 488d15f5b40000 488bce 488905???????? }
            // n = 7, score = 100
            //   4885c0               | dec                 eax
            //   0f8473010000         | cmp                 dword ptr [esp + 0x380], 0
            //   488bc8               | jne                 0x1b21
            //   e8????????           |                     
            //   488d15f5b40000       | xor                 eax, eax
            //   488bce               | dec                 eax
            //   488905????????       |                     

    condition:
        7 of them and filesize < 373760
}
Download all Yara Rules