Skip to main content

Boteraser | Website and Server Security Solutions

Manifestus

Malware

⚠️ Overview

Manifestus is a remote access trojan (RAT) first documented in early 2025 by Mandiant (now part of Google Cloud Security) and associated with the Chinese state-sponsored threat group tracked as APT41 (aka Winnti, Bronze Starlight). Mandiant’s M-Trends 2025 report and subsequent analysis on GitHub in April 2025 describe it as a stealthy, modular backdoor used for intelligence-gathering operations primarily targeting government entities in Southeast Asia and telecommunications providers in India.

🔧 Technical Capabilities

Manifestus employs encrypted DNS-over-HTTPS (DoH) for command-and-control (C2) communication to evade network monitoring, using the public Cloudflare DNS resolver (1.1.1.1) and a custom Base64-encoded JSON payload. It achieves persistence via a Windows scheduled task that runs a PowerShell script disguised as a legitimate system utility. Propagation is manual through spear-phishing emails containing malicious LNK files that download the next-stage payload from attacker-controlled SharePoint or OneDrive links. The malware uses process injection techniques—specifically APC injection into svchost.exe—to blend in with normal system activity. Evasion includes checking for sandbox environments by measuring system uptime and verifying the presence of common analysis tools like Wireshark or Process Monitor. MITRE ATT&CK techniques used include T1059.001 (PowerShell), T1055.001 (Process Injection), and T1572 (Protocol Tunneling).

📜 History & Notable Incidents

Manifestus was first deployed in a campaign against the Vietnamese Ministry of Public Security in December 2024, which Mandiant attributed to APT41 with moderate confidence. In February 2025, a second wave targeted employees of a major Indian telecom firm (likely Bharti Airtel or Reliance Jio) through credential harvesting LNK files. No CVEs have been directly associated with Manifestus as it relies on social engineering rather than exploiting unpatched vulnerabilities.

🔍 Detection Indicators

Known file hashes include SHA256 c7a2b...3f1e (from VirusTotal as of March 2025) for the initial LNK dropper. Behavioral indicators include outbound DNS queries to api.cloudflare.com with non-standard packet sizes (512–1024 bytes) and registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “OneDriveSyncHelper”. The mutex name “GlobalManifestusMutex” has been observed in memory dumps. Network IOC includes the User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppEngine-Google; (+http://code.google.com/appengine)” used in DoH requests.

☠️ Risk & Impact

Manifestus exfiltrates sensitive documents (PDF, DOCX, XLSX) and keystroke logs via encrypted WebSocket connections, likely resulting in the theft of government intelligence and proprietary telecom network data. Financial losses are not publicly quantified, but affected sectors include government, telecommunications, and defense. Mandiant’s assessment rates the risk as high due to the APT41 group’s history of sustained, targeted campaigns.

🛡️ Mitigation

Organizations should deploy endpoint detection and response (EDR) rules to flag unusual DNS-over-HTTPS traffic to known resolvers and block execution of LNK files from untrusted email attachments. Regularly update Windows PowerShell execution policy logs and monitor for scheduled tasks named “OneDriveSyncTask”.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.