Manjusaka — Malware Profile
Manjusaka is a Chinese-language intrusion framework, similar to Sliver and Cobalt Strike, with an ELF binary written in GoLang as the controller for Windows and Linux implants written in Rust. First identified in 2022, Manjusaka consists of multiple components, only one of which (a command and control module) is freely available.
MITRE ATT&CK techniques (10)
- T1016 System Network Configuration Discovery
- T1041 Exfiltration Over C2 Channel
- T1059.003 Windows Command Shell
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1113 Screen Capture
- T1132.001 Standard Encoding
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers