Researchers tied multiple malware families used in espionage campaigns to the TA428 cluster, linking the previously undocumented TManger RAT, Smanager/PhantomNet loaders, and the later Mail-O implant through shared code, export names, configuration structures, and command handling. NTT Security reported that TA428 used Poison Ivy, Cotx RAT, and EternalBlue during Operation LagTime IT before deploying TManger, a modular toolset made up of SetUp, MloadDll, and Client components that supports persistence, host reconnaissance, file operations, process execution, keylogging, and screen capture over RC4-encrypted command-and-control traffic.
Separate analysis found Smanager to be closely related to TManger and Albaniiutas, with droppers such as VVSup.exe and SACEventLog.exe unpacking Smanager_ssl.dll, modifying embedded configuration data, and establishing persistence either as a service or through rundll32 using the misspelled exported function Entery. SentinelLabs later assessed that Mail-O, used in a 2021 campaign against the FSB and other Russian government organizations while masquerading as Mail.ru Disk-O software, was a variant of PhantomNet/SManager rather than a Western intelligence tool, reinforcing links to TA428. Across the reporting, the actor was associated with intrusions affecting government and regional targets in East Asia, Southeast Asia, and Russia, showing continued development of a shared malware arsenal for intelligence collection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
SentinelOne assessed that the Mail-O malware used against Russian government organizations was a PhantomNet/SManager variant and that tooling overlaps with TManger supported attribution to the ThunderCats/TA428 umbrella rather than a Western intelligence service.
A Mail-O sample associated with the Russian government targeting campaign was first submitted to VirusTotal on 2021-06-05, enabling further analysis.
In May 2021, NKTsKI and Rostelecom announced that several Russian government institutions, including the FSB, were victims of an APT campaign involving Mail-O malware.
NTT Security Japan published analysis of Smanager, describing it as a malware family closely related to Tmanger and likely used in attacks against Vietnam-related organizations. The report detailed VVSup.exe and SACEventLog.exe droppers, Smanager_ssl.dll behavior, and overlaps with PhantomNet-related tooling.
Avast published reporting on an APT group targeting governmental agencies in East Asia.
In February 2020, NTT Security researchers investigated Operation LagTime IT, an intrusion campaign attributed to TA428. During the compromise, the actor used Poison Ivy and Cotx RAT for control, moved laterally with EternalBlue, and deployed the previously unseen Tmanger RAT on one host.
The Mail-O sample later analyzed by SentinelOne carried a compilation timestamp of 2019-12-20 02:13:01.
Palo Alto Networks Unit 42 reported BBSRAT attacks targeting Russian organizations and linked the activity to the Roaming Tiger cluster.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourceinsight-jp.nttsecurity.com
Open sourcedecoded.avast.io
Open sourceinsight-jp.nttsecurity.com
Open sourceunit42.paloaltonetworks.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.