Smanager is a Windows malware family assessed to be closely related to the Tmanger and Albaniiutas code lineage and likely represents an intermediate or variant branch within that cluster. It has been observed primarily in Vietnam-related contexts and has been discussed alongside activity affecting East and Southeast Asian targets. Attribution overlaps with clusters such as TA428, FunnyDream, PhantomNet, and Roaming Tiger/BBSRAT have been noted in research, but those links remain tentative rather than firmly established for Smanager itself.
Smanager is typically deployed through setup-stage executables that unpack and launch a DLL payload. The setup component modifies embedded configuration data and establishes persistence either by registering the DLL as a Windows service when administrative privileges are available or by invoking the DLL through rundll32 and its exported entrypoint when privileges are lower. Shared traits with related families include similar configuration structures, export naming, persistence logic, and loader behavior.
The principal observed payload variants include an SSL-enabled DLL and a TCP-based x64 variant. The SSL variant uses Microsoft Security Support Provider Interface for authentication and encrypted command-and-control communications, while the TCP variant performs similar functions without that SSPI-based protection. Once active, Smanager connects to its command-and-control infrastructure, collects host profiling data such as computer and host names, network and operating system details, language, username, default browser, and privilege level, and executes commands received from the operator.
Observed command support indicates that Smanager can transmit host information and download and execute additional PE payloads, including plugin-like modules. Its limited native command set and code patterns have led to the assessment that the observed Smanager DLLs function more as loader or staging components analogous to Tmanger's MlloadDll stage than as the final full-featured RAT client. Related research also identified strong implementation similarities with PhantomNet, including command handling and support for both TCP and SSL communication variants, suggesting a broader shared development lineage or code reuse ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Smanager is mentioned as malware tied by another report to overlapping C2 infrastructure and activity against Vietnam.
Referenced only in cited material, not discussed in the body of the article.
Tmangerの亜種または関連マルウェアとされるファミリ。Setup相当のEXEがDLLペイロードを展開し、サービス登録またはrundll32経由で実行する。DLLはC2へ接続し、端末情報の収集、追加実行ファイルのダウンロードと実行などを行う。記事ではMlloadDll相当と評価されているが、RAT/バックドア機能も備える。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.