Netskope Threat Labs

Chinoxy

ATP Sandbox Adv. HeuristicsAV

Chinoxy is a backdoor used since at least November 2018 to gain persistence and drop additional payloads during the FunnyDream campaign. Researchers attribute its use to Chinese-speaking threat actors.

First seen
September 2022
Last seen
September 2026

5 techniques across 2 tactics.

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

Alert Name
Generic.Trojan.Chinoxy.5FC8A6D5
Generic.Trojan.Chinoxy.A769C903
Win32.Backdoor.Chinoxy
Win32.Trojan.Chinoxy