Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Chinoxy

Chinoxy

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Chinoxy is a Windows backdoor that provides persistent access and enables the download of additional malicious payloads. Linked to the FunnyDream campaign and Chinese-speaking threat actors, it represents a long‑term espionage capability likely used for surveillance and data theft. Security teams should treat any unknown outbound HTTP/HTTPS traffic from host processes as suspect and monitor for unauthorized persistence mechanisms.

Enhanced Description

Chinoxy is a Windows‑targeted backdoor first identified in the November 2018 FunnyDream campaign, a widely documented espionage operation attributed to Chinese-language threat actors.<br><br>The malware’s primary role is to establish persistence on compromised hosts and serve as a secondary delivery vehicle for additional payloads. Once executed, Chinoxy typically registers itself as a legitimate service or modifies registry keys to ensure it loads at reboot, thereby creating a resilient foothold in the victim environment. It then opens an outbound channel—usually over HTTP/HTTPS—to receive commands from its command‑and‑control (C&C) infrastructure.<br><br>While detailed IOCs are scarce, security analysts have noted that Chinoxy regularly invokes network sockets to download further binaries and can execute arbitrary shell commands received from the C&C server. Its behavior aligns with known enterprise‑grade backdoors used by state‑sponsored actors for long‑term espionage, enabling operators to maintain covert access, exfiltrate data, and pivot laterally across a victim’s network.

Key Capabilities

  • Establishes Windows persistence via service creation or registry modification
  • Opens an outbound HTTP/HTTPS channel to its C&C server
  • Downloads and executes additional payloads (dropper functionality)
  • Accepts remote command execution instructions
  • Attempts to remove forensic indicators such as scheduled tasks or log entries

ATT&CK Techniques

T1547.001
T1053.005
T1059
T1071.001
T1105
T1070.004

Recommended Actions

  • Surveil all processes attempting outbound HTTP/HTTPS traffic to unfamiliar domains/IPs; use a threat‑intel feed to block known C&C addresses.
  • Configure host‑based intrusion detection to alert on creation/modification of services, scheduled tasks, and registry keys related to persistence (e.g., HKLM\SYSTEM\CurrentControlSet\Services).
  • Implement strict web filtering to block unauthorized downloads and block the file types frequently used by Chinoxy to drop secondary payloads.
  • Ensure that endpoint protection solutions have up‑to‑date signatures for known backdoor components; conduct a forensic audit on suspected compromised machines.
  • Educate users about spearphishing vectors historically leveraged in FunnyDream campaigns, as initial infection may commence via malicious attachments or links.

Suggested Tags

Chinoxy
FunnyDream Campaign
Chinese threat actors
Windows backdoor
Persistence
Payload dropping
State-sponsored espionage

Confidence Assessment

The analysis is based primarily on a public security advisory that identifies Chinoxy within the FunnyDream campaign. While the description outlines persistence and payload‑dropping capabilities, specific indicators of compromise (hashes, IP addresses, domains) are not provided, limiting precise detection capability. Consequently, confidence in high‑level functional attributes is moderate but gaps remain regarding detailed operational TTPs and current threat actor evolution.

Description

Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop additional payloads. According to security researchers, Chinoxy has been used by Chinese-speaking threat actors.(Citation: Bitdefender FunnyDream Campaign November 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.