Campaign, Jul 2018 to Nov 2020.View on attack.mitre.org
FunnyDream was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Southeast Asia. Security researchers linked the FunnyDream campaign to possible Chinese-speaking threat actors through the use of the Chinoxy backdoor and noted infrastructure overlap with the TAG-16 threat group.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
During FunnyDream, the threat actors used ipconfig for discovery on remote systems. |
| T1018 Remote System Discovery |
During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks. |
| T1047 Windows Management Instrumentation |
During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands. |
| T1049 System Network Connections Discovery |
During FunnyDream, the threat actors used netstat to discover network connections on remote systems. |
| T1057 Process Discovery |
During FunnyDream, the threat actors used Tasklist on targeted systems. |
| T1059.003 Windows Command Shell |
During FunnyDream, the threat actors used `cmd.exe` to execute the wmiexec.vbs script. |
| T1059.005 Visual Basic |
During FunnyDream, the threat actors used a Visual Basic script to run remote commands. |
| T1082 System Information Discovery |
During FunnyDream, the threat actors used Systeminfo to collect information on targeted hosts. |
| T1105 Ingress Tool Transfer |
During FunnyDream, the threat actors downloaded additional droppers and backdoors onto a compromised system. |
| T1560.001 Archive via Utility |
During FunnyDream, the threat actors used 7zr.exe to add collected files to an archive. |
| T1583.001 Domains |
For FunnyDream, the threat actors registered a variety of domains. |
| T1585.002 Email Accounts |
For FunnyDream, the threat actors likely established an identified email account to register a variety of domains that were used during the campaign. |
| T1588.001 Malware |
For FunnyDream, the threat actors used a new backdoor named FunnyDream. |
| T1588.002 Tool |
For FunnyDream, the threat actors used a modified version of the open source PcShare remote administration tool. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.