A new Chinese state-backed hacking group (APT) has infected more than 200 systems across Southeast Asia with malware over the past two years. According to security researchers at Bitdefender , the attacks /infections are part of a cyber espionage campaign . The Chinese group behind them has been dubbed FunnyDream .

The attacks are primarily targeting governments in Southeast Asia . Bitdefender did not say exactly which countries were affected. However, a few months ago, Kaspersky Lab had identified victims of the FunnyDream group in Malaysia, Taiwan, the Philippines, and Vietnam (where most of the victims were located ).
Both security firms say that the Chinese APT group FunnyDream is still active in cyber espionage, with the aim of stealing sensitive documents from infected devices. The espionage is focused on national security and industry-related issues.
Similar attacks were discovered in 2018
According to Bitdefender researchers, most of these attacks have followed a simple pattern and combine three malware payloads: Chinoxy, PCShare , and FunnyDream (the malware from which the group takes its name).
The three malware serve different purposes. Chinoxy is the original malware, the one that acts as a backdoor to gain initial access. Next comes PCShare (a well-known Chinese open-source remote access trojan), which is deployed via Chinoxy and is used to explore infected devices. Finally, FunnyDream. It is the most powerful of the three malware. According to researchers, it has many advanced features and capabilities that allow it to collect and steal data.

"Looking at the timeline of the tool's use, we can see that the criminals started by developing a series of tools intended for quick exploration and data, and later decided to bring a comprehensive toolkit, specifically the FunnyDream toolkit, to enable long-term monitoring," Liviu Arsene, a security researcher at Bitdefender, told ZDNet.
According to the researcher, many infections of government infrastructure have been identified, aimed at espionage and likely politically motivated .
“Considering that Southeast Asia faces many economic and trade issues related to the shift of supply chains from China to Southeast Asia, as well as US-China relations, these infections may be part of Chinese campaigns targeting Southeast Asian government institutions for potential espionage,” the researcher said, adding that some countries in the region recently had elections, which brought changes in governance. These changes are of interest to China. The government could use a state-run hacking group for espionage, in order to see if local regimes are ideologically and politically aligned with China’s interests.
Source: ZDNet
