ATT&CKSoftwareFunnyDream

FunnyDream

S1044

Malware.View on attack.mitre.org

About this malware

FunnyDream is a backdoor with multiple components that was used during the FunnyDream campaign since at least 2019, primarily for execution and exfiltration.

Techniques used37

Procedure examples37

TechniqueProcedure example
T1001
Data Obfuscation

FunnyDream can send compressed and obfuscated packets to C2.

T1005
Data from Local System

FunnyDream can upload files from victims' machines.

T1010
Application Window Discovery

FunnyDream has the ability to discover application windows via execution of `EnumWindows`.

T1012
Query Registry

FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string.

T1016
System Network Configuration Discovery

FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies.

T1018
Remote System Discovery

FunnyDream can collect information about hosts on the victim network.

T1025
Data from Removable Media

The FunnyDream FilePakMonitor component has the ability to collect files from removable devices.

T1027.013
Encrypted/Encoded File

FunnyDream can Base64 encode its C2 address stored in a template binary with the `xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_-` or
`xyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvw_=` character sets.

T1033
System Owner/User Discovery

FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`.

T1036.004
Masquerade Task or Service

FunnyDream has used a service named `WSearch` for execution.

T1041
Exfiltration Over C2 Channel

FunnyDream can execute commands, including gathering user information, and send the results to C2.

T1047
Windows Management Instrumentation

FunnyDream can use WMI to open a Windows command shell on a remote machine.

T1055.001
Dynamic-link Library Injection

The FunnyDream FilepakMonitor component can inject into the Bka.exe process using the `VirtualAllocEx`, `WriteProcessMemory` and `CreateRemoteThread` APIs to load the DLL component.

T1056.001
Keylogging

The FunnyDream Keyrecord component can capture keystrokes.

T1057
Process Discovery

FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`.

View all 37 procedure examples

Groups that use it0

None recorded.

Campaigns1

References1

  1. Bitdefender FunnyDream Campaign November 2020 Open source
    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.