Tmanger is a modular Windows remote access trojan associated with the China-linked TA428 activity cluster. It was used in Operation LagTime IT against East Asian government organizations, where it was deployed after compromise and lateral movement using MS17-010 exploitation. Tmanger has also been delivered through compromised Able Desktop software-update activity targeting Mongolian organizations. The malware comprises Setup, MloadDll, and Client stages: Setup establishes privilege-dependent persistence, MloadDll decrypts configuration and loads the Client, and Client provides the primary remote-access functions. Administrator-level infections can persist through a Windows service, while non-administrator infections use Run-key persistence. Tmanger collects host, operating-system, architecture, drive, and user information; communicates with command-and-control infrastructure using RC4-encrypted traffic; and supports command execution, directory and file operations, file exfiltration, keylogging, screen capture, and cleanup. Related malware includes Smanager, Albaniiutas, and PhantomNet, which share code and structural characteristics with the Tmanger family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit MS17-010 for lateral movement, NETBIOS scanner for environmental investigations, tools to steal credentials and new RATs such as Tmanger or nccTrojan.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Used a tool to exploit MS17-010 for lateral movement, NETBIOS scanner for environmental investigations, tools to steal credentials and new RATs such as Tmanger or nccTrojan.
TmangerにはAlbaniiutas以外にも、類似したマルウェアが存在します。今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
Tmanger has following functions: Remote Shell (cmd.exe); Remote Shell (powershell.exe)... nccTrojan has following functions: Remote Shell.
As a result of our analysis, we consider that the functions of this RAT are as follows: • Command execution by PowerShell
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
Configuration data lists C&C servers on ports 443, 8080, 80, and 5222; sections describe C&C communication for Poison Ivy, Tmanger, and nccTrojan.
It is used to download three cab files (‘o.cab’, ‘nbt.cab’ and ‘in.cab’) from the C&C server, and execute the files stored in the cab files.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/payload delivered in later phases of Operation StealthyTrident alongside HyperBro and PlugX.
Malware noted for sharing the unusual exported function name 'Entery' and overlapping function layout/strings with Mail-O, and correlated in the content with TA428.
Related malware noted for sharing the distinctive misspelled export name 'Entery' and overlapping function layout/strings with Mail-O, used as part of the attribution linkage to TA428.
A LuckyMouse-associated implant mentioned only as historical context from an earlier campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.