FunnyDream can send compressed and obfuscated packets to C2.2
tool
FunnyDream S1044
- Type
- malware
- Platform
- Windows
- Created
- 23 September 2022
- Last modified
- 11 April 2024
FunnyDream is a backdoor with multiple components that was used during the FunnyDream campaign since at least 2019, primarily for execution and exfiltration.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1044
FunnyDream can upload files from victims' machines.34
FunnyDream has the ability to discover application windows via execution of EnumWindows.5
FunnyDream can check Software\Microsoft\Windows\CurrentVersion\Internet Settings to extract the ProxyServer string.6
FunnyDream can parse the ProxyServer string in the Registry to discover http proxies.7
FunnyDream can collect information about hosts on the victim network.8
Standing S1044
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
97th percentile · 97% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
89th percentile · 89% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
29th percentile · 71% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1044
816 distinct rules cover the 37 techniques recorded for this tool. The 877 technique-to-rule mappings resolve to 816 distinct rules, because one rule can cover several techniques. 558 Sigma · 258 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org