Chinoxy

S1041

Malware.View on attack.mitre.org

About this malware

Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop additional payloads. According to security researchers, Chinoxy has been used by Chinese-speaking threat actors.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Chinoxy has encrypted its configuration file.

T1036.005
Match Legitimate Resource Name or Location

Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file.

T1140
Deobfuscate/Decode Files or Information

The Chinoxy dropping function can initiate decryption of its config file.

T1547.001
Registry Run Keys / Startup Folder

Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`.

T1574.001
DLL

Chinoxy can use a digitally signed binary ("Logitech Bluetooth Wizard Host Process") to load its dll into memory.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Bitdefender FunnyDream Campaign November 2020 Open source
    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.