Chinoxy is a Windows remote access trojan and backdoor used in cyberespionage operations, including sustained campaigns against government organizations in Southeast Asia since at least 2018. It establishes persistence after initial compromise and supports follow-on activity by deploying additional malware and executing attacker tools. In FunnyDream-associated operations, Chinoxy deployed a modified PcShare RAT and executed the ccf32 document-collection tool. Chinoxy has also been associated with the China-linked threat actors BRONZE EDGEWOOD and TA459; TA459 used it against media personnel in April 2022.
Chinoxy abuses DLL side-loading through a legitimate, digitally signed Logitech Bluetooth Wizard Host Process executable to load its malicious DLL. Observed persistence mechanisms include Windows Run registry entries and Startup-folder deployment. It also uses legitimate-looking filenames to conceal malicious components. Some variants decode configuration data from numeric values and communicate with command-and-control infrastructure using a custom protocol incorporating Blowfish encryption. Chinoxy has been delivered through targeted phishing emails carrying malicious RTF attachments generated with the Royal Road weaponizer, which exploits Microsoft Office Equation Editor vulnerabilities. Its role in documented intrusions is primarily persistent remote access and execution of additional espionage tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Opening the email attachment, “Please help to CHECK.doc,” opens a decoy Word document. And at the same time, it exploits CVE-2018-0798 in the background. CVE-2018-0798 is a Remote Code Execution (RCE) vulnerability in Microsoft’s Equation Editor (EQNEDT32). Microsoft released a fix for it on January 9, 2018.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE EDGEWOOD ... Tools ... Chinoxy, Cobalt Strike, FunnyDream, Md_client, Nishang Post Exploitation Framework, PCShare, Zuguo
FunnyDream uses Chinoxy and FunnyDream Backdoor. Chinoxy is a RAT that has been used by FunnyDream since around 2018.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Our analysis revealed that the file behaves similarly... It creates a folder (c:\windows\tasks) and drops config and PE files into it.
Opening the email attachment... opens a decoy Word document. And at the same time, it exploits CVE-2018-0798 in the background.
Our analysis revealed that the file behaves similarly... It creates a folder (c:\windows\tasks) and drops config and PE files into it.
MITRE ... Persistence T1543.003 Create or Modify System Process: Windows Service
Our analysis revealed that the file behaves similarly... It creates a folder (c:\windows\tasks) and drops config and PE files into it.
Instead of LBTServ.dll containing the final payload, it loads a shellcode from a separate file and injects itself into svchost.exe.
MITRE ... Persistence T1543.003 Create or Modify System Process: Windows Service
MITRE ... Defense Evasion T1027 Obfuscated Files or Information
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Instead of LBTServ.dll containing the final payload, it loads a shellcode from a separate file and injects itself into svchost.exe.
Chinoxy is a RAT that has been used by FunnyDream since around 2018. It decoded the config using two numeric data and communicates with the C&C server using its original protocol using Blowfish.
It then contacts instructor[.]giize[.]com... where the payload is hosted.
51 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE EDGEWOOD threat profile.
Backdoor malware referenced as present on a remote machine used in file staging/copy operations.
Chinoxy is a backdoor used by the same threat actor lineage, delivered through DLL search order hijacking with a legitimate Logitech binary and malicious LBTServ.dll. Older variants loaded an external configuration file named k1.ini containing C2 information; newer variants decrypt and load shellcode from a file and download the next payload. It collects data from infected computers.
Chinoxy is a backdoor malware used to gain persistence on victim machines, allowing remote access and control by threat actors. It is typically delivered via malicious document attachments in spear-phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.