• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
chinese hackers using new manjusaka hacking framework similar to cobalt

Chinese Hackers Using New Manjusaka Hacking Framework Similar to Cobalt Strike

You are here: Home / General Cyber Security News / Chinese Hackers Using New Manjusaka Hacking Framework Similar to Cobalt Strike
August 2, 2022

Scientists have disclosed a new offensive framework named Manjusaka that they phone a “Chinese sibling of Sliver and Cobalt Strike.”

“A absolutely practical version of the command-and-management (C2), composed in GoLang with a Person Interface in Simplified Chinese, is freely readily available and can create new implants with customized configurations with ease, raising the chance of broader adoption of this framework by destructive actors,” Cisco Talos reported in a new report.

Sliver and Cobalt Strike are legitimate adversary emulation frameworks that have been used by menace actors to carry out article-exploitation activities this kind of as network reconnaissance, lateral movement, and facilitating the deployment of adhere to-on payloads.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Penned in Rust, Manjusaka — which means “cow flower” — is advertised as an equal to the Cobalt Strike framework with abilities to focus on both equally Windows and Linux operating programs. Its developer is considered to be situated in the GuangDong location of China.

CyberSecurity

“The implant consists of a multitude of distant entry trojan (RAT) capabilities that include some common operation and a devoted file administration module,” the researchers noted.

Some of the supported functions involve executing arbitrary instructions, harvesting browser qualifications from Google Chrome, Microsoft Edge, Qihoo 360, Tencent QQ Browser, Opera, Courageous, and Vivaldi, collecting Wi-Fi passwords, capturing screenshots, and getting complete system info.

It is really also built to start the file management module to have out a broad selection of activities this kind of as enumerating information as perfectly as handling documents and directories on the compromised system.

Manjusaka Hacking Framework

On the other hand, the ELF variant of the backdoor, whilst together with most of the functionalities as its Windows counterpart, isn’t going to include the potential to obtain qualifications from Chromium-based browsers and harvest Wi-Fi login passwords.

Also, element of the Chinese language framework is a C2 server executable that is coded in Golang and is out there on GitHub at “hxxps://github[.]com/YDHCUI/manjusaka.” A 3rd part is an admin panel built on the Gin web framework that enables an operator to create the Rust implant.

The server binary, for its component, is engineered to observe and administer an contaminated endpoint, in addition to building the ideal Rust implants depending on the running technique and issuing the necessary commands.

That mentioned, the chain of evidence suggests that it’s both below lively progress or its parts are provided to other actors as a assistance.

CyberSecurity

Talos explained it designed the discovery all through its investigation of a maldoc an infection chain that leverages COVID-19-themed lures in China to supply Cobalt Strike beacons on infected units, introducing the same menace actor also utilized the implants from the Manjusaka framework in the wild.

The results get there months following it emerged that malicious actors have been observed abusing yet another legitimate adversary simulation software package termed Brute Ratel (BRc4) in their attacks in an try to stay underneath the radar and evade detection.

“The availability of the Manjusaka offensive framework is an sign of the attractiveness of extensively offered offensive systems with each crimeware and APT operators,” the scientists reported.

“This new attack framework incorporates all the attributes that a person would count on from an implant, on the other hand, it is published in the most modern-day and moveable programming languages. The developer of the framework can quickly integrate new target platforms like MacOSX or a lot more unique flavors of Linux as the kinds working on embedded products.”

Discovered this short article interesting? Comply with THN on Fb, Twitter  and LinkedIn to read a lot more exclusive written content we article.


Some components of this article are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Google Patches Critical Android Bluetooth Flaw in August Security Bulletin
Next Post: LockBit Ransomware Exploits Windows Defender to Sideload Cobalt Strike Payload Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.