Cisco Talos disclosed Manjusaka, an offensive framework used in the wild and marketed by its developers as an alternative to Cobalt Strike and Sliver. The toolkit includes a Go-based ELF command-and-control server with a Simplified Chinese interface and Rust-based implants for both Windows and Linux. Talos found a publicly accessible C2 binary on GitHub capable of generating customized payloads, and reported that the Windows implant supports broad remote-access and post-compromise functions including command execution, file management, screenshot capture, browser and Wi-Fi credential theft, Navicat credential theft, and host reconnaissance.
Talos also tied the framework to a multi-stage intrusion campaign that used COVID-19-themed Microsoft Word lures referencing Golmud City in Qinghai Province. That infection chain ultimately deployed a Cobalt Strike beacon, while investigators also observed a Manjusaka implant communicating with the same infrastructure, including IP address 39.104.90.45, indicating operational overlap between the tools. Talos stopped short of firm attribution, but said available indicators suggest the framework developer is Chinese-speaking and may be based in Guangdong, China.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A GitHub IOC entry documented Manjusaka's internal packaging and unpacking, including raw-deflated hex-encoded blobs and a change from version 05 onward that moved EXE and ELF binaries into a plugins folder. The publication also listed hashes, infrastructure, user-agent strings, domains, URLs, and forensic indicators associated with Manjusaka artifacts observed in the wild.
Talos found a publicly available Manjusaka command-and-control binary and repository on GitHub at github.com/YDHCUI/manjusaka. The C2 could generate customized Rust-based payloads for Windows and Linux.
Cisco Talos reported a new offensive framework called Manjusaka being used in the wild and marketed by its developers as similar to Cobalt Strike. Talos identified a Go-based ELF C2 server with a Simplified Chinese interface and Rust-based implants for Windows and Linux.
During the campaign investigation, Talos found a Manjusaka implant communicating with the same IP address, 39.104.90.45, used by the Cobalt Strike beacon. This indicated the same threat actor was using both Cobalt Strike and Manjusaka implants.
Cisco Talos investigated a malicious campaign using COVID-19-themed Microsoft Word documents referencing Golmud City in Qinghai Province. The infection chain used a VBA macro, Metasploit shellcode, and ultimately loaded a Cobalt Strike beacon communicating with 39.104.90.45.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceblog.talosintelligence.com
Open sourcetalos-intelligence-site.s3.amazonaws.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.