During FunnyDream, the threat actors used ipconfig for discovery on remote systems.4
campaign
FunnyDream C0007
- First seen
- July 2018
- Last seen
- November 2020
- Created
- 20 September 2022
- Last modified
- 31 July 2026
FunnyDream was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Southeast Asia. Security researchers linked the FunnyDream campaign to possible Chinese-speaking threat actors through the use of the Chinoxy backdoor and noted infrastructure overlap with the TAG-16 threat group.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0007
During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.5
During FunnyDream, the threat actors used wmiexec.vbs to run remote commands.6
During FunnyDream, the threat actors used netstat to discover network connections on remote systems.7
During FunnyDream, the threat actors used Tasklist on targeted systems.8
During FunnyDream, the threat actors used cmd.exe to execute the wmiexec.vbs script.9
Standing C0007
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
38th percentile · 62% of 56 ATT&CK campaigns have more Enterprise techniques.
25th percentile · 75% of 56 ATT&CK campaigns have more tactics spanned.
93rd percentile · 93% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
77th percentile · 77% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0007
444 distinct rules cover the 14 techniques recorded for this campaign. The 482 technique-to-rule mappings resolve to 444 distinct rules, because one rule can cover several techniques. 298 Sigma · 146 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org