Malware.View on attack.mitre.org
FunnyDream is a backdoor with multiple components that was used during the FunnyDream campaign since at least 2019, primarily for execution and exfiltration.
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
FunnyDream can send compressed and obfuscated packets to C2. |
| T1005 Data from Local System |
FunnyDream can upload files from victims' machines. |
| T1010 Application Window Discovery |
FunnyDream has the ability to discover application windows via execution of `EnumWindows`. |
| T1012 Query Registry |
FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string. |
| T1016 System Network Configuration Discovery |
FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies. |
| T1018 Remote System Discovery |
FunnyDream can collect information about hosts on the victim network. |
| T1025 Data from Removable Media |
The FunnyDream FilePakMonitor component has the ability to collect files from removable devices. |
| T1027.013 Encrypted/Encoded File |
FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or |
| T1033 System Owner/User Discovery |
FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`. |
| T1036.004 Masquerade Task or Service |
FunnyDream has used a service named `WSearch` for execution. |
| T1041 Exfiltration Over C2 Channel |
FunnyDream can execute commands, including gathering user information, and send the results to C2. |
| T1047 Windows Management Instrumentation |
FunnyDream can use WMI to open a Windows command shell on a remote machine. |
| T1055.001 Dynamic-link Library Injection |
The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component. |
| T1056.001 Keylogging |
The FunnyDream Keyrecord component can capture keystrokes. |
| T1057 Process Discovery |
FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.