Chinoxy is a Windows remote access trojan and backdoor associated with China-aligned espionage activity, including operations linked to the FunnyDream cluster and campaigns attributed to TA459. It has been observed in use since at least 2018, with related tradecraft and infrastructure overlaps tying it to a longer-running intrusion set active from at least the mid-2010s. Targeting has included organizations and individuals in South Asia and Southeast Asia, including telecommunications and media-related victims.
Chinoxy is commonly delivered through spearphishing emails carrying malicious Royal Road-generated RTF documents that exploit Microsoft Equation Editor vulnerabilities such as CVE-2018-0798. In multiple campaigns, execution relied on DLL search order hijacking using a legitimate digitally signed Logitech executable to load a malicious DLL, which then decrypted or loaded the next-stage payload. Variants have also been observed using process injection into svchost.exe and masquerading under benign-looking names such as eoffice.exe to reduce suspicion.
The malware is described as using encoded configuration data and a custom command-and-control protocol protected with Blowfish. It is used to establish persistence and provide remote access on compromised systems. Reporting also places Chinoxy in operational contexts where compromised hosts were used for staging or copying files to remote machines, consistent with broader espionage objectives. Its recurring use alongside Royal Road lures, DLL sideloading tradecraft, and other backdoors indicates a role as a persistent access implant in targeted intrusion campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Opening the email attachment, “Please help to CHECK.doc,” opens a decoy Word document. And at the same time, it exploits CVE-2018-0798 in the background. CVE-2018-0798 is a Remote Code Execution (RCE) vulnerability in Microsoft’s Equation Editor (EQNEDT32). Microsoft released a fix for it on January 9, 2018.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE EDGEWOOD ... Tools ... Chinoxy, Cobalt Strike, FunnyDream, Md_client, Nishang Post Exploitation Framework, PCShare, Zuguo
FunnyDream uses Chinoxy and FunnyDream Backdoor. Chinoxy is a RAT that has been used by FunnyDream since around 2018.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Our analysis revealed that the file behaves similarly... It creates a folder (c:\windows\tasks) and drops config and PE files into it.
Opening the email attachment... opens a decoy Word document. And at the same time, it exploits CVE-2018-0798 in the background.
Our analysis revealed that the file behaves similarly... It creates a folder (c:\windows\tasks) and drops config and PE files into it.
MITRE ... Persistence T1543.003 Create or Modify System Process: Windows Service
Our analysis revealed that the file behaves similarly... It creates a folder (c:\windows\tasks) and drops config and PE files into it.
Instead of LBTServ.dll containing the final payload, it loads a shellcode from a separate file and injects itself into svchost.exe.
MITRE ... Persistence T1543.003 Create or Modify System Process: Windows Service
MITRE ... Defense Evasion T1027 Obfuscated Files or Information
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Instead of LBTServ.dll containing the final payload, it loads a shellcode from a separate file and injects itself into svchost.exe.
Chinoxy is a RAT that has been used by FunnyDream since around 2018. It decoded the config using two numeric data and communicates with the C&C server using its original protocol using Blowfish.
It then contacts instructor[.]giize[.]com... where the payload is hosted.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE EDGEWOOD threat profile.
Backdoor malware referenced as present on a remote machine used in file staging/copy operations.
Chinoxy is a backdoor used by the same threat actor lineage, delivered through DLL search order hijacking with a legitimate Logitech binary and malicious LBTServ.dll. Older variants loaded an external configuration file named k1.ini containing C2 information; newer variants decrypt and load shellcode from a file and download the next payload. It collects data from infected computers.
Chinoxy is a backdoor malware used to gain persistence on victim machines, allowing remote access and control by threat actors. It is typically delivered via malicious document attachments in spear-phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.