Manjusaka

S1156

Malware.View on attack.mitre.org

About this malware

Manjusaka is a Chinese-language intrusion framework, similar to Sliver and Cobalt Strike, with an ELF binary written in GoLang as the controller for Windows and Linux implants written in Rust. First identified in 2022, Manjusaka consists of multiple components, only one of which (a command and control module) is freely available.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1016
System Network Configuration Discovery

Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes.

T1041
Exfiltration Over C2 Channel

Manjusaka data exfiltration takes place over HTTP channels.

T1059.003
Windows Command Shell

Manjusaka can execute arbitrary commands passed to it from the C2 controller via `cmd.exe /c`.

T1071.001
Web Protocols

Manjusaka has used HTTP for command and control communication.

T1082
System Information Discovery

Manjusaka performs basic system profiling actions to fingerprint and register the victim system with the C2 controller.

T1083
File and Directory Discovery

Manjusaka can gather information about specific files on the victim system.

T1113
Screen Capture

Manjusaka can take screenshots of the victim desktop.

T1132.001
Standard Encoding

Manjusaka communication includes a client-created session cookie with base64-encoded information representing information from the victim system.

T1555
Credentials from Password Stores

Manjusaka extracts credentials from the Windows Registry associated with Premiumsoft Navicat, a utility used to facilitate access to various database types.

T1555.003
Credentials from Web Browsers

Manjusaka gathers credentials from Chromium-based browsers.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Talos Manjusaka 2022 Open source
    Asheer Malhotra & Vitor Ventura. (2022, August 2). Manjusaka: A Chinese sibling of Sliver and Cobalt Strike. Retrieved September 4, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.