Albaniiutas is a Windows malware family closely related to Tmanger and assessed to have been used in espionage activity associated with TA428. It has been observed in lures targeting Mongolian political entities, including decoy content themed around members of Mongolia’s Citizens’ Representative Hural, indicating a focus on government or politically relevant organizations in East Asia.
Albaniiutas is modular and mirrors the role separation seen in Tmanger, with setup, loader, and client components. Infection has been observed beginning from a RAR archive containing an executable disguised as an XLSX document. When launched, the initial executable opens a decoy document and drops additional components. Execution flow depends on privilege level. In administrator contexts, the malware decrypts and installs components into system locations, uses a legitimate Microsoft Visual J# utility for DLL sideloading, and establishes persistence by registering a malicious DLL as a service. In non-administrator contexts, it writes components into user-accessible locations, establishes persistence through a Run key, then continues execution through the same sideloading chain. The malware also modifies embedded paths to match the local environment and timestomps dropped files to reduce visibility.
Albaniiutas uses multiple cryptographic routines during staging and runtime, including RC4 and AES-256, to decrypt configuration data and embedded payloads. Its loader ultimately decrypts and launches ClientX.dll, which functions as the primary remote access trojan component. The client retrieves updated command-and-control information from attacker-controlled web content, collects host information, and communicates with its controller using encrypted traffic. Supported operator commands include shell execution through cmd.exe, file upload, file download, and idle control behavior.
Code and design similarities strongly suggest shared development lineage with Tmanger and related families such as Smanager and PhantomNet. Reported overlaps include component structure, cryptographic material, export naming conventions, and plugin-loading logic. Albaniiutas is therefore best understood as part of an evolving malware lineage used in targeted intrusions linked to China-aligned espionage activity, particularly against Mongolian and other East Asian targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
今回はそうしたTmangerに関連するマルウェアの中から、Albaniiutasを紹介します。... ClientX.dllはTmangerのClientと同様にRAT本体です。
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Thumtaisは、Proxy経由でC2サーバへ通信する機能を有しています... 新検体では認証プロキシに対応しており... C2サーバに通信をします。
RC4のデコードが完了した後、デコードされたURLに対してアクセスし、ダウンロードしたHTMLファイルから新しいC&CサーバーのIPアドレスをデコードします。
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PhantomNetと同じRC4復号キーを使用するとされる別マルウェアで、開発者共通性の根拠として言及されている。
TA428 toolkit backdoor referenced for network infrastructure adjacency/intersections with Zupdax-related infrastructure, supporting the assessment of cooperation/tool sharing between Space Pirates and TA428.
Referenced only in cited material, not discussed in the body of the article.
Tmangerの最新版または後継と推定される関連マルウェア。SmanagerとExport関数名、暗号鍵の特徴、MlloadDllのGetPluginObject呼び出しなどの類似点がある。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.