Executive Summary
Chinoxy is a Windows backdoor that provides persistent access and enables the download of additional malicious payloads. Linked to the FunnyDream campaign and Chinese-speaking threat actors, it represents a long‑term espionage capability likely used for surveillance and data theft. Security teams should treat any unknown outbound HTTP/HTTPS traffic from host processes as suspect and monitor for unauthorized persistence mechanisms.
Enhanced Description
Chinoxy is a Windows‑targeted backdoor first identified in the November 2018 FunnyDream campaign, a widely documented espionage operation attributed to Chinese-language threat actors.<br><br>The malware’s primary role is to establish persistence on compromised hosts and serve as a secondary delivery vehicle for additional payloads. Once executed, Chinoxy typically registers itself as a legitimate service or modifies registry keys to ensure it loads at reboot, thereby creating a resilient foothold in the victim environment. It then opens an outbound channel—usually over HTTP/HTTPS—to receive commands from its command‑and‑control (C&C) infrastructure.<br><br>While detailed IOCs are scarce, security analysts have noted that Chinoxy regularly invokes network sockets to download further binaries and can execute arbitrary shell commands received from the C&C server. Its behavior aligns with known enterprise‑grade backdoors used by state‑sponsored actors for long‑term espionage, enabling operators to maintain covert access, exfiltrate data, and pivot laterally across a victim’s network.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based primarily on a public security advisory that identifies Chinoxy within the FunnyDream campaign. While the description outlines persistence and payload‑dropping capabilities, specific indicators of compromise (hashes, IP addresses, domains) are not provided, limiting precise detection capability. Consequently, confidence in high‑level functional attributes is moderate but gaps remain regarding detailed operational TTPs and current threat actor evolution.
Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop additional payloads. According to security researchers, Chinoxy has been used by Chinese-speaking threat actors.(Citation: Bitdefender FunnyDream Campaign November 2020)