ATT&CKCampaignsFunnyDream

FunnyDream

C0007

Campaign, Jul 2018 to Nov 2020.View on attack.mitre.org

About this campaign

FunnyDream was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Southeast Asia. Security researchers linked the FunnyDream campaign to possible Chinese-speaking threat actors through the use of the Chinoxy backdoor and noted infrastructure overlap with the TAG-16 threat group.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

During FunnyDream, the threat actors used ipconfig for discovery on remote systems.

T1018
Remote System Discovery

During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.

T1047
Windows Management Instrumentation

During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands.

T1049
System Network Connections Discovery

During FunnyDream, the threat actors used netstat to discover network connections on remote systems.

T1057
Process Discovery

During FunnyDream, the threat actors used Tasklist on targeted systems.

T1059.003
Windows Command Shell

During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script.

T1059.005
Visual Basic

During FunnyDream, the threat actors used a Visual Basic script to run remote commands.

T1082
System Information Discovery

During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts.

T1105
Ingress Tool Transfer

During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system.

T1560.001
Archive via Utility

During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive.

T1583.001
Domains

For FunnyDream, the threat actors registered a variety of domains.

T1585.002
Email Accounts

For FunnyDream, the threat actors likely established an identified email account to register a variety of domains that were used during the campaign.

T1588.001
Malware

For FunnyDream, the threat actors used a new backdoor named FunnyDream.

T1588.002
Tool

For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software8

References3

  1. Bitdefender FunnyDream Campaign November 2020 Open source
    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.
  2. Kaspersky APT Trends Q1 2020 Open source
    Global Research and Analysis Team. (2020, April 30). APT trends report Q1 2020. Retrieved September 19, 2022.
  3. Recorded Future Chinese Activity in Southeast Asia December 2021 Open source
    Insikt Group. (2021, December 8). Chinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia. Retrieved September 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.