Asheer Malhotra & Vitor Ventura. (2022, August 2). Manjusaka: A Chinese sibling of Sliver and Cobalt Strike. Retrieved September 4, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareManjusaka | Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes. |
| T1041 Exfiltration Over C2 Channel |
MalwareManjusaka | Manjusaka data exfiltration takes place over HTTP channels. |
| T1059.003 Windows Command Shell |
MalwareManjusaka | Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`. |
| T1071.001 Web Protocols |
MalwareManjusaka | Manjusaka has used HTTP for command and control communication. |
| T1082 System Information Discovery |
MalwareManjusaka | Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller. |
| T1083 File and Directory Discovery |
MalwareManjusaka | Manjusaka can gather information about specific files on the victim system. |
| T1113 Screen Capture |
MalwareManjusaka | Manjusaka can take screenshots of the victim desktop. |
| T1132.001 Standard Encoding |
MalwareManjusaka | Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system. |
| T1555 Credentials from Password Stores |
MalwareManjusaka | Manjusaka extracts credentials from the Windows Registry associated with Premiumsoft Navicat, a utility used to facilitate access to various database types. |
| T1555.003 Credentials from Web Browsers |
MalwareManjusaka | Manjusaka gathers credentials from Chromium-based browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.