FunnySwitch is a Windows .NET backdoor associated with Chinese espionage activity and most consistently linked to APT41/Winnti-related operations, including activity tracked under FishMonger and RedHotel/TAG-22. It has been observed in campaigns targeting organizations in Hong Kong and Russia, and has appeared within broader intrusion sets aimed at government, telecommunications, media, research, gaming, and other high-value sectors. FunnySwitch has also been described as tailored tooling used in more selective operations rather than indiscriminate malware deployment.
The malware is typically loaded through DLL search order hijacking or DLL sideloading chains and has also been used as a loader for follow-on payloads such as Cobalt Strike. Reported tradecraft includes early-bird code injection and in-memory loading of additional components. FunnySwitch shares multiple implementation features with Crosswalk, leading researchers to assess that the two were likely developed by the same authors or development team.
At the capability level, FunnySwitch can collect system information and execute arbitrary JScript code received from operators, providing flexible post-compromise control. Its role in intrusion chains indicates use as a backdoor and post-exploitation platform rather than a simple first-stage downloader. Comparisons with other APT41-linked tooling have also highlighted overlap in KCP-related code patterns, further situating it within a broader ecosystem of Chinese intrusion tooling.
FunnySwitch is part of a recurring toolset that has included ShadowPad, Spyder, PlugX, BIOPASS RAT, SprySOCKS, and Cobalt Strike. Its operational use aligns with long-running espionage campaigns focused on maintaining covert access, staging additional payloads, and supporting hands-on-keyboard activity inside victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Use funnyswitch to load Cobalt Strike and use early bird code injection technique
Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.
A named tool in FishMonger’s toolset; no further technical detail is provided in the content.
A tailored malware family used for specific operations against high-value targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.