Tmanger is a modular Windows remote access trojan used by the China-linked threat actor TA428 in cyberespionage operations against East Asian government organizations. It was identified during investigation of Operation LagTime IT in February 2020, where it was deployed by Poison Ivy after attackers used EternalBlue for lateral movement. The campaign initially compromised systems through Royal Road-generated RTF lure documents exploiting CVE-2018-0798; Tmanger served as a follow-on implant rather than the initial exploitation payload.
Tmanger comprises setup, loader, and client components. The setup component checks administrative privileges and establishes persistence through a Windows service when elevated or a per-user Run entry otherwise. The loader decrypts configuration data and unpacks the client payload. The client collects operating-system, architecture, drive, host, and user information and communicates with command-and-control servers using RC4-encrypted traffic. Its capabilities include remote shell and PowerShell execution, process execution, directory enumeration, file retrieval and exfiltration, file writing, copying and deletion, keylogging, screen capture, and cleanup.
Tmanger was also distributed through the compromised Able Desktop software update channel during Operation StealthyTrident against Mongolian organizations. In July 2020, it replaced HyperBro on at least one affected system. That operation involved tooling associated with TA428 and LuckyMouse, but these overlaps do not establish exclusive attribution of the campaign to either actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit MS17-010 for lateral movement, NETBIOS scanner for environmental investigations, tools to steal credentials and new RATs such as Tmanger or nccTrojan.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During Operation StealthyTrident ... the attackers used Tmanger, attributed to TA428, and Zupdax, associated with Space Pirates.
TmangerにはAlbaniiutas以外にも、類似したマルウェアが存在します。今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
Tmanger has following functions: Remote Shell (cmd.exe); Remote Shell (powershell.exe)... nccTrojan has following functions: Remote Shell.
As a result of our analysis, we consider that the functions of this RAT are as follows: • Command execution by PowerShell
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
Configuration data lists C&C servers on ports 443, 8080, 80, and 5222; sections describe C&C communication for Poison Ivy, Tmanger, and nccTrojan.
It is used to download three cab files (‘o.cab’, ‘nbt.cab’ and ‘in.cab’) from the C&C server, and execute the files stored in the cab files.
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/payload delivered in later phases of Operation StealthyTrident alongside HyperBro and PlugX.
Malware noted for sharing the unusual exported function name 'Entery' and overlapping function layout/strings with Mail-O, and correlated in the content with TA428.
Related malware noted for sharing the distinctive misspelled export name 'Entery' and overlapping function layout/strings with Mail-O, used as part of the attribution linkage to TA428.
A LuckyMouse-associated implant mentioned only as historical context from an earlier campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.