Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:14:48 UTC Home > List all groups > List all tools > List all groups using tool FunnySwitch Tool: FunnySwitch Names FunnySwitch RouterGod Category Malware Type Loader, Backdoor Description (Trend Micro) FunnySwitch is a .NET Framework backdoor that usually starts with the “MITRE – Hijack Execution Flow: DLL Search Order Hijacking” technique and executes inside a legal process that was mentioned and analyzed by Positive Technologies in 2020. Information Malpedia Last change to this tool card: 27 December 2022 Download this tool card in JSON format All groups using tool FunnySwitch Changed Name Country Observed APT groups APT 41 2012-Jul 2025 Earth Lusca 2019-Sep 2024 RedHotel, TAG-22 2021-2022 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=21b1dd5b-e372-44eb-a8c9-e9d6626d8ced Page 1 of 2 Winnti Group, Wicked Panda 2010-Mar 2021   4 groups listed (4 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=21b1dd5b-e372-44eb-a8c9-e9d6626d8ced https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=21b1dd5b-e372-44eb-a8c9-e9d6626d8ced Page 2 of 2