LiteManager is a legitimate remote monitoring and management tool that has been abused by threat actors as an intrusion-enabling payload. In observed malicious use, it has been delivered through phishing campaigns and installed via MSI packages to provide remote access to compromised systems. Because it is legitimate administration software, its use can blend with normal remote-support activity and may reduce suspicion while giving operators persistent interactive access.
Russia-aligned intrusion activity attributed to UAC-0050, also associated with the DaVinci Group and the Fire Cells branding, has used LiteManager in campaigns primarily targeting Ukrainian organizations. Reported targeting has included governmental, defense-related, energy, gas, media, manufacturing, and financial-sector entities, as well as other organizations connected to Ukraine. In these operations, LiteManager formed part of broader campaigns involving social engineering, impersonation themes, and follow-on objectives including intelligence collection, financial theft, and psychological operations.
Within UAC-0050 tradecraft, LiteManager appears alongside other remote access and malware tooling such as Remcos, NetSupport Manager, sLoad, and Remote Manipulator System, reflecting a pattern of abusing legitimate remote administration software for covert access. High-confidence reporting supports its use as a remote-access payload delivered through phishing rather than as a self-propagating or destructive malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On December 25th, the same Russian IP ‘109.71.247[.]168’ ... Once unpacked it revealed an executable used to deploy the LiteManager MSI.
"...the threat actor known to drop legitimate remote access software like LiteManager..."
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The VBS script’s purpose was to download an obfuscated and weaponized version of the SSH client PuTTY through the following Bitbucket folder.
85 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate remote access/administration software used by the actor for remote control and persistence on victim systems.
A remote management tool previously used by UAC-0050 as part of its intrusion activity.
LiteManager was used by UAC-0050 as a remote access payload delivered through phishing emails, PDF lures, cloud-hosted archives, and password-protected containers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.