Malware.View on attack.mitre.org
Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop additional payloads. According to security researchers, Chinoxy has been used by Chinese-speaking threat actors.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Chinoxy has encrypted its configuration file. |
| T1036.005 Match Legitimate Resource Name or Location |
Chinoxy has used the name `eoffice.exe` in attempt to appear as a legitimate file. |
| T1140 Deobfuscate/Decode Files or Information |
The Chinoxy dropping function can initiate decryption of its config file. |
| T1547.001 Registry Run Keys / Startup Folder |
Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`. |
| T1574.001 DLL |
Chinoxy can use a digitally signed binary ("Logitech Bluetooth Wizard Host Process") to load its dll into memory. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.