SManager is a Windows malware loader that communicates with command-and-control servers, profiles compromised hosts, and downloads and executes additional Portable Executable payloads. Its DLL-based components receive server commands and collect computer and host names, network addressing information, operating-system version, language, username, default browser, and administrative-privilege status. SSL variants use Microsoft's Security Support Provider Interface for authentication and encrypted communications; TCP variants operate without that SSPI-based protection. Observed components have a limited command set centered on host profiling and payload loading rather than a full remote-access toolset.
Setup components unpack an embedded DLL, modify its configuration, and select execution behavior according to available privileges. With administrator privileges, they install and launch the payload as a Windows service, providing persistence. Without administrator privileges, they execute the DLL through the Windows DLL execution utility. SManager shares configuration structures, exported-function conventions, and implementation characteristics with Tmanger, Albaniiutas, and PhantomNet.
SManager has been observed in attacks against Vietnamese organizations and in Earth Kurma operations, where a KRNRAT user-mode backdoor retrieves it as a subsequent payload. Earth Kurma targets government and government-related telecommunications organizations in Southeast Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload from the C&C server would be the so-called SManager.
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
今回は私達がTmangerの亜種であると考えているSmanagerについて紹介します。Smanager_ssl.dllは実行されると、C&Cサーバーとコネクションを確立します。その際、Microsoft Security Service Provider Interfaceを利用して、認証や通信の暗号化を行っています。C&Cサーバーとのコネクション確立後、C&Cサーバーから受信したデータに応じてコマンドを実行します。
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers noted that the malware’s persistence was established via a scheduled task that called the malicious DLL’s export, ‘Entery’.
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Named final-stage payload retrieved through the KRNRAT backdoor chain. The report identifies its GetPluginInformation export but does not describe its capabilities in detail.
Smanager is mentioned as malware tied by another report to overlapping C2 infrastructure and activity against Vietnam.
Referenced only in cited material, not discussed in the body of the article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.