funnyswitch
FunnySwitch is a .NET backdoor associated with China-aligned espionage activity and linked in reporting to APT41-related operations, FishMonger, and RedHotel/TAG-22. It is described as tailored malware used in specific operations and is typically loaded via DLL search order hijacking. Reporting places it within toolsets that also include ShadowPad, Spyder, Cobalt Strike, SprySOCKS, and BIOPASS RAT. FunnySwitch has been cited in connection with FishMonger, a Chinese cyberespionage group believed to be operated by contractor I-SOON under the broader Winnti Group umbrella, and with RedHotel, a Chinese state-sponsored threat group active since at least 2019 that has targeted government organizations in Southeast Asia and other sectors globally. Separate reporting noted a JScript execution feature via SharpJSHandler that resembled functionality in FunnySwitch, but no broader tooling overlap with APT41 was established in that case. No specific FunnySwitch indicators of compromise were provided in the source content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.
FunnySwitch is a .NET backdoor typically loaded via DLL search order hijacking.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.
A named tool in FishMonger’s toolset; no further technical detail is provided in the content.
A tailored malware family used for specific operations against high-value targets.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.