Chinoxy

MITRE ATT&CK: S1041 View on attack.mitre.org

Aliases: Chinoxy

First seen
2018-11-01 00:00:00
Malware type
backdoor, dropper
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:38:25

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn

Context

Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop additional payloads. According to security researchers, Chinoxy has been used by Chinese-speaking threat actors.

Detection coverage

  • 1 YARA rules
  • 139 Sigma rules

Malware & tools used

  • DLL (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)

Used by threat actors

  • FunnyDream (campaign)

Detection rules

  • MALPEDIA_Win_Chinoxy_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • proofpoint.com — Above Fold And Your Inbox Tracing State Aligned Activity Targeting Journalists (report)
  • medium.com — New Version Of Chinoxy Backdoor Using Covid19 Document Lure 83Fa294C0746 (report)
  • nao-sec.org — Royal Road Redive (report)
  • community.riskiq.com — 5Fe2Da7F (report)
  • community.riskiq.com — 56Fa1B2F (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Chinoxy (report)
  • Trend Micro — Wp Finding Aptx Attributing Attacks Via Mitre Ttps (report)
  • fortinet.com — Pivnoxy And Chinoxy Puppeteer Analysis (report)
  • medium.com — How To Unpack Chinoxy Backdoor And Decipher The Configuration Of The Backdoor 4Ffd98Ca2A02 (report)
  • bitdefender.com — Bitdefender Whitepaper Chinese Apt (report)
  • go.recordedfuture.com — Cta 2021 1208 (report)
  • MITRE ATT&CK — S1041 (report)

External references