TF-MAL-elf.manjusaka
📛 Threat Title
Malware family: Manjusaka
Description
ThreatFox malware family `elf.manjusaka`. Printable name: Manjusaka.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.manjusaka
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.manjusaka
IOC database
- Type
- domain
- Value
elf.manjusaka- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.manjusaka
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.manjusaka
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Manjusaka is a Chinese-language intrusion framework, similar to Sliver and Cobalt Strike, with an ELF binary written in GoLang as the controller for Windows and Linux implants written in Rust.
-
web:blog.talosintelligence.com
Manjusaka design Manjusaka attack framework The malware implant is a RAT family called " Manjusaka ." The C2 is an ELF binary written in GoLang, while the implants are written in the Rust programming language, consisting of a variety of capabilities that can be used to control the infected endpoint, including executing arbitrary commands.
-
web:cve.nohackme.com
Manjusaka is a Chinese-language intrusion framework, similar to Sliver and Cobalt Strike, with an ELF binary written in GoLang as the controller for Windows and Linux implants written in Rust. First identified in 2022, Manjusaka consists of multiple components, only one of which (a command and control module) is freely available.
-
web:hivepro.com
Manjusaka is a new attack framework that mimics Cobalt Strike and Sliver. The new malware family implants are written in the Rust programming language and are compatible with Windows and Linux.
-
web:jfl0w.github.io
Researchers with the Cisco Talos Intelligence Group have recently discovered a new family of RAT implant malware called Manjusaka being used in the wild. Advertised as an imitation of the Cobalt Strike framework, Manjusaka is a fully functional command and control (C2) framework written in GoLang with a GUI in Simplified Chinese.
-
web:malpedia.caad.fkie.fraunhofer.de
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
-
web:umbrella.cisco.com
Implants for this new malware family are written in the Rust language for Windows and Linux. Threat actors can find a freely available and fully functional version of the command and control (C2) written in GoLang with a user interface in Simplified Chinese.
-
web:www.broadcom.com
Manjusaka attack framework A newly discovered offensive framework named Manjusaka is being used in the wild according to the latest reports. Advertised as an alternative to other toolsets commonly used by threat actors such as Cobalt Strike or Sliver, Manjusaka makes use of Rust-based implants and binaries written in GoLang. The malware implants have various functionalities, including ...
-
web:www.safeaeon.com
Researchers have disclosed a new hacking framework called Manjusaka that they call a "Chinese sibling of Sliver and Cobalt Strike." The attack framework is identified as an imitation of the Cobalt Strike framework. The experts reported that Rust language for Windows and Linux is used to write the implants for the new malware family .
-
web:www.socinvestigation.com
Cisco Talos recently discovered a new attack framework called " Manjusaka " being used in the wild that has the potential to become prevalent across the threat landscape. This framework is advertised as an imitation of the Cobalt Strike framework. The implants for the new malware family are written in the Rust language for Windows and Linux.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.