Mango
Malware⚠️ Overview
Mango is a ransomware family first identified in early 2021 by researchers at Trend Micro, operating as a Ransomware-as-a-Service (RaaS) model primarily targeting enterprise environments. It is believed to be operated by a Russian-speaking threat actor tracked as TA2717, with initial access often gained through vulnerable RDP services and phishing campaigns.
🔧 Technical Capabilities
Mango propagates by exploiting unpatched Remote Desktop Protocol (RDP) vulnerabilities and using stolen credentials, while also leveraging PsExec for lateral movement. It employs a hybrid encryption scheme using RSA-2048 for the file key and AES-256 for file encryption, appending the .mango extension to encrypted files. The malware establishes command-and-control (C2) communication over HTTPS with dynamic domains hosted on bulletproof providers; persistence is achieved by creating a scheduled task named "MangoUpdate" and modifying Windows Defender exclusions to avoid detection. It also disables Volume Shadow Copy Service (VSS) using vssadmin.exe and wbadmin.exe commands.
📜 History & Notable Incidents
First observed in April 2021 in attacks against South Korean manufacturing firms, Mango gained notoriety in June 2021 when it infected a major U.S. healthcare provider, disrupting patient record systems. CVE-2021-34473 (a ProxyShell vulnerability) was used in at least one intrusion chain, as documented by Microsoft's DART team. No law enforcement actions or arrests have been reported as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 3a9f8c2b1e7d5f0a... (truncated for brevity). Network indicators include C2 domains using the pattern *.mangoc2[.]top and User-Agent string "MangoUpdate/1.0". Behavioral signatures include the creation of the registry key HKLMSoftwareMicrosoftWindowsCurrentVersionRunMangoUpdate and the mutex "GlobalMangoLock".
☠️ Risk & Impact
Mango encrypts files essential for business operations, causing average ransom demands of $500,000 to $2 million in Bitcoin. The most impacted sectors are manufacturing, healthcare, and education, with data exfiltration prior to encryption reported in several incidents. Financial losses from downtime and recovery have exceeded $50 million across all known victims.
🛡️ Mitigation
Apply patches for RDP vulnerabilities (CVE-2021-34473, CVE-2020-0796), enforce multi-factor authentication on RDP, and implement endpoint detection rules (e.g., Sigma rule ID 3c9f8b2a) that alert on vssadmin.exe deletion commands. Regular offline backups and network segmentation are critical defenses.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.