ATT&CKReferencesTalos Manjusaka 2022

Talos Manjusaka 2022

Asheer Malhotra & Vitor Ventura. (2022, August 2). Manjusaka: A Chinese sibling of Sliver and Cobalt Strike. Retrieved September 4, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareManjusaka

Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes.

T1041
Exfiltration Over C2 Channel
MalwareManjusaka

Manjusaka data exfiltration takes place over HTTP channels.

T1059.003
Windows Command Shell
MalwareManjusaka

Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`.

T1071.001
Web Protocols
MalwareManjusaka

Manjusaka has used HTTP for command and control communication.

T1082
System Information Discovery
MalwareManjusaka

Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller.

T1083
File and Directory Discovery
MalwareManjusaka

Manjusaka can gather information about specific files on the victim system.

T1113
Screen Capture
MalwareManjusaka

Manjusaka can take screenshots of the victim desktop.

T1132.001
Standard Encoding
MalwareManjusaka

Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system.

T1555
Credentials from Password Stores
MalwareManjusaka

Manjusaka extracts credentials from the Windows Registry associated with Premiumsoft Navicat, a utility used to facilitate access to various database types.

T1555.003
Credentials from Web Browsers
MalwareManjusaka

Manjusaka gathers credentials from Chromium-based browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.