Tmanger
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
攻撃者はEternal Blueを悪用して同一ネットワーク上のいくつかのホストに移動することに成功すると、そのうちの1つのホスト上で興味深いマルウェアを動かし始めました。 | PDBに Tmanger と書かれたRATは今までに見たことがない未知のマルウェアでした。... 今回はTA428がOperation LagTime ITの中で使用したTmangerというRATについて紹介しました。
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PDBに Tmanger と書かれたRATは今までに見たことがない未知のマルウェアでした。... 今回はTA428がOperation LagTime ITの中で使用したTmangerというRATについて紹介しました。
Techniques & procedures
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Execution
2 techniques
Execution
コマンド 説明 1, 17 特定のプロセスの起動 ... 34 CreateProcessによるプロセスの起動
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
Persistence
2 techniques
Persistence
Privilege Escalation
2 techniques
Privilege Escalation
Stealth
1 technique
Stealth
Discovery
2 techniques
Discovery
Lateral Movement
1 technique
Lateral Movement
Collection
2 techniques
Collection
IOCs tracked for this family
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware noted for sharing the unusual exported function name 'Entery' and overlapping function layout/strings with Mail-O, and correlated in the content with TA428.
TA428-attributed malware referenced as present in the same broader operational context as Zupdax (Space Pirates-associated), suggesting tool sharing or joint operations; no further technical detail provided here.
RAT delivered by the legitimate Able Desktop software after HyperBro, replacing it in July 2020. It uses RC4-encrypted configuration and communications over raw TCP, supports keylogging, screen capture, fallback C2, and file exfiltration.
TA428に利用されるRAT。SetUp、MloadDll、Clientの3パートで構成され、永続化、サービス登録、設定復号、C&C通信、端末情報収集、ファイル操作、プロセス起動、キーログ取得、画面キャプチャ取得などの機能を持つ。通信はRC4で暗号化される。
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.