Operation Manul is a targeted spearphishing and malware campaign assessed as likely conducted by or on behalf of the government of Kazakhstan against political opponents and related individuals. Known victims included Kazakh journalists, dissidents living in Europe, lawyers, family members, and associates connected to disputes involving the Kazakh state, including people linked to Mukhtar Ablyazov and the independent newspaper Respublika. Activity associated with the campaign has been linked to targeting dating back to at least 2012, with documented spearphishing operations in 2015. The operation relied on phishing emails themed around invoices, legal matters, software updates, and Kazakhstan-related current affairs to deliver commodity remote access trojans, primarily JRat and Bandook. JRat provided cross-platform remote access and surveillance capabilities, including keylogging, password recovery, webcam access, shell access, process listing, registry editing, and anti-virtualization checks. Bandook was used on Windows systems and employed process hollowing to inject into suspended browser processes. Its modular architecture enabled additional surveillance and collection functions such as screen capture, webcam and audio recording, file search and exfiltration, shell access, wireless network enumeration, MTP device listing, and USB monitoring. The campaign demonstrated capabilities consistent with espionage-focused intrusion activity, including initial access via spearphishing, persistence, defense evasion, process injection, credential theft, keylogging, and exfiltration. Investigators also observed infrastructure suggesting the operators were running multiple simultaneous intrusion campaigns in a hackers-for-hire model rather than a single isolated operation. Earlier speculation about links to Appin was later assessed as likely incorrect, and no direct technical link was established between Operation Manul and Arcanum Global Intelligence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously documented Bandook espionage campaign targeting journalists and dissidents in Europe; referenced as historically related and with sample overlap to Bandidos.
A spear-phishing and malware campaign targeting Kazakh dissidents, journalists, lawyers, and associates involved in litigation with the government of Kazakhstan. The campaign primarily used commercially available RATs for surveillance and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.