FunnyDream is a Windows backdoor and modular cyberespionage toolset used for persistent access, surveillance, and information theft. It has been deployed against government-sector organizations in Southeast Asia in operations observed from November 2018 through 2020, alongside Chinoxy and modified PcShare malware. FunnyDream is associated with the China-linked espionage group BRONZE EDGEWOOD, also known as Red Hariasa.
The backdoor supports remote shells, command execution, file upload and download, directory listing, file execution, and user-information collection. It can use Windows Management Instrumentation to launch a command shell on a remote machine, supporting lateral movement. Command-and-control communications support TCP and UDP, with some samples using HTTP or SOCKS proxies. Certain variants disguise XOR-obfuscated, zLib-compressed communications within HTTP-formatted traffic and retrieve proxy settings from the Windows Registry.
Collection components monitor document changes, gather Office documents and PDFs, capture screenshots, record keystrokes, and stage collected information in local archives. FilePakMonitor detects removable-drive insertion and collects matching files from attached media. Persistence mechanisms include Run registry entries, Startup-folder execution, and automatically starting services. FilePakMonitor also abuses phantom DLL hijacking in the Windows Search service to execute with SYSTEM privileges and has attempted injection into a Bkav antivirus process. Other evasion behaviors include identifying Bkav processes, programmatically dismissing antivirus dialogs, and deleting deployment traces. FunnyDream has been deployed through compromised domain-controller shares; its initial infection vector is not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE EDGEWOOD ... Tools ... Chinoxy, Cobalt Strike, FunnyDream, Md_client, Nishang Post Exploitation Framework, PCShare, Zuguo
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
63 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE EDGEWOOD threat profile.
A backdoor used by threat actors in the FunnyDream campaign.
Backdoor that gathers user information from a targeted system using whoami variants.
Supports TCP and UDP for command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.