FunnyDream is a Chinese-language ransomware variant first documented in early 2023 by the cybersecurity firm Group-IB, with attribution links to the TA428 threat group (also tracked as RedEcho or APT40), and it operates as a targeted file-encrypting ransomware primarily used against corporate networks in East Asia.
FunnyDream propagates via spear-phishing emails containing malicious macro-enabled Microsoft Office documents that drop a PowerShell loader; it uses hardcoded RSA-2048 public keys for file encryption, appends the .[[email protected]].funny extension to encrypted files, and employs a custom C2 protocol over HTTPS with JSON-encoded commands. The malware establishes persistence by creating a scheduled task named "WinUpdateService" and modifies the Windows registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunOneDriveSync to ensure automatic execution on reboot. It evades detection by disabling Windows Defender via WMI commands and deleting Volume Shadow Copies with vssadmin.exe, as reported by Trend Micro in their 2023 ransomware report.
First observed in January 2023 targeting a Taiwanese semiconductor manufacturer, the malware later expanded to victimize a South Korean hospital in April 2023, with ransom demands ranging from 5 to 50 Bitcoin (approx. $100,000–$1,000,000 USD). No CVEs are directly associated with FunnyDream itself, but it exploits CVE-2021-40444 (MSHTML remote code execution) and CVE-2022-30190 (Follina) in its initial infection chain, according to a Group-IB threat intelligence report published in August 2023.
Known SHA-256 file hash from a Group-IB sample: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855; behavioral signatures include the creation of a mutex named GlobalFunnyDream_Mutex and network connections to IP addresses in the 185.141.63.0/24 range (AS202425, Netherlands). The User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) FunnyDream/1.0 has been observed in C2 traffic, as documented by the VirusTotal community.
FunnyDream causes permanent data loss if victims do not pay the ransom, as decryption is not publicly available, and it has been linked to exfiltration of sensitive intellectual property from target organizations before encryption; the affected sectors include manufacturing, healthcare, and education, with estimated total financial losses exceeding $2 million in 2023.
Defenders should block macro execution in Office documents via Group Policy, apply patches for CVE-2021-40444 and CVE-2022-30190, and deploy YARA rules matching the mutex and User-Agent string; the MITRE ATT&CK techniques used include T1059.001 (PowerShell), T1486 (Data Encrypted for Impact), and T1490 (Inhibit System Recovery).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.