Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

ManageEngine Endpoint Central

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs.

T1566.001Spearphishing AttachmentEvidence1

The attack starts with WhatsApp messages sent from compromised accounts. These messages typically contain only a heavily obfuscated VBScript file designed to evade detection.

Execution

2 techniques
T1059.005Visual BasicEvidence1

Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software.

T1204.002Malicious FileEvidence2

Once a victim downloads and executes the attachment, a multi-stage infection process begins.

Persistence

1 technique
T1112Modify RegistryEvidence1

These scripts modify the Windows Registry to disable User Account Control (UAC) protections and retrieve a ZIP archive containing ManageEngine Endpoint Central.

Privilege Escalation

2 techniques
T1548Abuse Elevation Control MechanismEvidence1

The command is launched using the ShellExecute method with the runas verb, causing Windows to request administrative privileges before the registry change can be applied.

T1548.002Bypass User Account ControlEvidence1

These scripts modify the Windows Registry to disable User Account Control (UAC) protections

Stealth

1 technique
T1218.007MsiexecEvidence3

Once extracted and executed, this package installs itself silently using Windows Installer and connects back to attacker-controlled servers.

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

These scripts modify the Windows Registry to disable User Account Control (UAC) protections and retrieve a ZIP archive containing ManageEngine Endpoint Central.

Lateral Movement

1 technique
T1021Remote ServicesEvidence1

The setup script installs it silently so the user sees nothing, then connects the newly installed agent to attacker-controlled management servers.

Command and Control

2 techniques
T1105Ingress Tool TransferEvidence5

If a Windows user opens the malicious file, the VBScript downloads two additional scripts from attacker-controlled servers.

T1219Remote Access ToolsEvidence5

The attack eventually installs ManageEngine Endpoint Central, a legitimate system management tool commonly used by IT administrators to oversee devices from a centralized platform.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.