Manjusaka is a web-based offensive framework and remote access malware family positioned as an imitation of Cobalt Strike. It has been observed in the wild since at least 2022 and is associated with a Go-based command-and-control component and Rust-based implants for Windows and Linux. Reporting has noted multiple indicators consistent with Chinese-language development and possible use by China-nexus intrusion activity, although public attribution to a specific operator remains unconfirmed.
The framework can generate customized implants and supports post-compromise remote administration and file operations. The Windows implant provides arbitrary command execution, host and environment reconnaissance, screenshot capture, and extensive file-management functions including enumerating, creating, deleting, moving, copying, reading, and writing files and directories. It also supports credential theft from Chromium-based browsers, harvesting of Wi-Fi credentials, and extraction of database access credentials associated with Navicat from Windows systems. The Linux variant offers similar RAT and file-management capabilities and collects system information from standard operating system sources, but available reporting indicates it lacks the Windows-focused browser and Wi-Fi credential harvesting features.
Manjusaka communicates over HTTP and has been observed embedding compressed and Base64-encoded victim fingerprinting data in a session cookie. Stolen information is exfiltrated through its command-and-control channel. The framework has also been linked to intrusion activity using lure documents and multi-stage infection chains alongside Cobalt Strike, indicating it can be deployed as part of broader post-exploitation operations rather than as a standalone initial access mechanism.
Manjusaka is notable for its cross-platform design, single-file packaging approach, and role as a modern offensive framework intended to provide operators with customizable implants and conventional RAT functionality across Windows and Linux environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Create directories on the file system. Get and set the current working directory. Delete files and remove directories on disk. Move files between two locations. Copy the file to a new location and delete the old copy. Read and write data to and from the file.
Collect browser credentials: Specifically for Chromium-based browsers using the query: SELECT signon_realm, username_value, password_value FROM logins ;
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
Account information from /etc/passwd and group lists of users.
Get information about the current network connections (TCP and UDP) established on the system, including Local network addresses, remote addresses and owning Process IDs (PIDs).
Manjusaka is web based imitation of the Cobalt Strike framework... ITW payload Rust binaries ... 45[.]137.117.219 39[.]104.90.45 95[.]179.151.49 71[.]115.193.247:9000 119[.]28.101.125 104[.]225.234.200 Mozilla/5.0 ...
The sample makes HTTP requests to a fixed address http[:]//39[.]104[.]90[.]45/global/favicon.png that contains a fixed session cookie defined by the sample rather than by the server.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of a fast-evolving single-file attack framework tracked by Cisco Talos since 2022; no additional capabilities described in the provided content.
Manjusaka is a cross-platform (Windows and Linux) malware framework developed in Rust, featuring backdoor and C2 capabilities, and is positioned as a potential successor to Cobalt Strike for China-nexus actors.
A Rust-based cross-platform implant and offensive framework with a Go-based C2. It provides remote access capabilities including arbitrary command execution, file management, system reconnaissance, screenshot capture, browser credential theft, Wi-Fi credential harvesting, and Navicat credential theft on Windows, with similar functionality on Linux minus some credential theft features.
Remote access malware that extracts database access credentials from Windows Registry entries associated with Navicat.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.