Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

SyncFuture TSM

SyncFuture TSM (Terminal Security Management System) is a legitimate commercial remote monitoring and management / endpoint security product developed by Nanjing Zhongke Huasai Technology Co., Ltd in China and associated with SyncFutureTec Company Limited utilities. In the reported campaign, it was repurposed by attackers as an all-in-one espionage framework. eSentire reported its use in an ongoing multi-stage cyber-espionage operation targeting Indian users via phishing emails impersonating the Income Tax Department of India. The infection chain used a malicious ZIP archive containing a visible executable, "Inspection Document Review.exe," to sideload a malicious DLL, perform anti-debugging checks, contact external infrastructure, download additional payloads, bypass UAC via a COM-based technique, and masquerade as explorer.exe by modifying the PEB. A later stage retrieved "180.exe" from eaxwwyr[.]cn and adapted behavior based on whether Avast Free Antivirus was present. If Avast was detected, a Blackmoon (KRBanker) variant automated GUI interaction to add attacker files to Avast exclusions, including C:\Windows\SysWOW64\msres\Setup.exe. "Setup.exe" was described as a SyncFutureTec Company Limited utility that wrote "mysetup.exe" to disk; "mysetup.exe" was assessed to be SyncFuture TSM. Once deployed, the repurposed SyncFuture TSM provided persistent remote access, remote control of infected endpoints, user activity recording, monitoring, centralized logging/orchestration, and data exfiltration. Supporting components included MANC.exe for service orchestration and extensive logging, service-based persistence including SafeBoot registry modifications, and batch scripts that created custom directories, weakened ACLs by granting broad permissions, manipulated Desktop-folder permissions, and performed cleanup/restoration. Reported infrastructure and configuration associated with the campaign included C2 endpoint 8.217.152[.]225:80 requesting /1bin, download domain eaxwwyr[.]cn, server IP 49.204.200[.]100 in YTSysConfig.ini, and a connection check to timecha[.]com:443. The campaign was described as suspected cyber espionage and had not been attributed to any known threat actor or group.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

The activity was identified by eSentire’s Threat Response Unit in early December 2025 and begins with messages designed to lure recipients into downloading a malicious archive. The emails appear as penalty notices from the Indian government’s tax office.

Persistence

1 technique
T1543.003Windows ServiceEvidence1

The next stage deploys a custom toolkit built around batch scripts to weaken system defences and install a core component as a Windows service, configured to run even in "safe" mode.

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence1

The next stage deploys a custom toolkit built around batch scripts to weaken system defences and install a core component as a Windows service, configured to run even in "safe" mode.

Command and Control

1 technique
T1219Remote Access ToolsEvidence3

"...final payload is the SyncFuture TSM... marketed as a legitimate enterprise tool, it is repurposed... as a powerful... espionage framework... establish resilient persistence..."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.