Chinoxy
MITRE ATT&CK: S1041 View on attack.mitre.org
Aliases: Chinoxy
- First seen
- 2018-11-01 00:00:00
- Malware type
- backdoor, dropper
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:38:25
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn
Context
Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop additional payloads. According to security researchers, Chinoxy has been used by Chinese-speaking threat actors.
Detection coverage
- 1 YARA rules
- 139 Sigma rules
Malware & tools used
- DLL (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Used by threat actors
- FunnyDream (campaign)
Detection rules
- MALPEDIA_Win_Chinoxy_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- proofpoint.com — Above Fold And Your Inbox Tracing State Aligned Activity Targeting Journalists (report)
- medium.com — New Version Of Chinoxy Backdoor Using Covid19 Document Lure 83Fa294C0746 (report)
- nao-sec.org — Royal Road Redive (report)
- community.riskiq.com — 5Fe2Da7F (report)
- community.riskiq.com — 56Fa1B2F (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Chinoxy (report)
- Trend Micro — Wp Finding Aptx Attributing Attacks Via Mitre Ttps (report)
- fortinet.com — Pivnoxy And Chinoxy Puppeteer Analysis (report)
- medium.com — How To Unpack Chinoxy Backdoor And Decipher The Configuration Of The Backdoor 4Ffd98Ca2A02 (report)
- bitdefender.com — Bitdefender Whitepaper Chinese Apt (report)
- go.recordedfuture.com — Cta 2021 1208 (report)
- MITRE ATT&CK — S1041 (report)