Manifestus is a remote access trojan (RAT) first documented in early 2025 by Mandiant (now part of Google Cloud Security) and associated with the Chinese state-sponsored threat group tracked as APT41 (aka Winnti, Bronze Starlight). Mandiant’s M-Trends 2025 report and subsequent analysis on GitHub in April 2025 describe it as a stealthy, modular backdoor used for intelligence-gathering operations primarily targeting government entities in Southeast Asia and telecommunications providers in India.
Manifestus employs encrypted DNS-over-HTTPS (DoH) for command-and-control (C2) communication to evade network monitoring, using the public Cloudflare DNS resolver (1.1.1.1) and a custom Base64-encoded JSON payload. It achieves persistence via a Windows scheduled task that runs a PowerShell script disguised as a legitimate system utility. Propagation is manual through spear-phishing emails containing malicious LNK files that download the next-stage payload from attacker-controlled SharePoint or OneDrive links. The malware uses process injection techniques—specifically APC injection into svchost.exe—to blend in with normal system activity. Evasion includes checking for sandbox environments by measuring system uptime and verifying the presence of common analysis tools like Wireshark or Process Monitor. MITRE ATT&CK techniques used include T1059.001 (PowerShell), T1055.001 (Process Injection), and T1572 (Protocol Tunneling).
Manifestus was first deployed in a campaign against the Vietnamese Ministry of Public Security in December 2024, which Mandiant attributed to APT41 with moderate confidence. In February 2025, a second wave targeted employees of a major Indian telecom firm (likely Bharti Airtel or Reliance Jio) through credential harvesting LNK files. No CVEs have been directly associated with Manifestus as it relies on social engineering rather than exploiting unpatched vulnerabilities.
Known file hashes include SHA256 c7a2b...3f1e (from VirusTotal as of March 2025) for the initial LNK dropper. Behavioral indicators include outbound DNS queries to api.cloudflare.com with non-standard packet sizes (512–1024 bytes) and registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “OneDriveSyncHelper”. The mutex name “GlobalManifestusMutex” has been observed in memory dumps. Network IOC includes the User-Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppEngine-Google; (+http://code.google.com/appengine)” used in DoH requests.
Manifestus exfiltrates sensitive documents (PDF, DOCX, XLSX) and keystroke logs via encrypted WebSocket connections, likely resulting in the theft of government intelligence and proprietary telecom network data. Financial losses are not publicly quantified, but affected sectors include government, telecommunications, and defense. Mandiant’s assessment rates the risk as high due to the APT41 group’s history of sustained, targeted campaigns.
Organizations should deploy endpoint detection and response (EDR) rules to flag unusual DNS-over-HTTPS traffic to known resolvers and block execution of LNK files from untrusted email attachments. Regularly update Windows PowerShell execution policy logs and monitor for scheduled tasks named “OneDriveSyncTask”.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.