Skip to main content

Boteraser | Website and Server Security Solutions

ManItsMe

Malware

⚠️ Overview

ManItsMe is a remote access trojan (RAT) first documented in late 2022 by researchers at the Chinese cybersecurity firm 360 Netlab, attributed to the advanced persistent threat group APT41 (also known as Winnti or Barium). The malware is primarily used for intelligence gathering and persistent remote access to compromised networks, falling under the categories of backdoor and information stealer.

🔧 Technical Capabilities

ManItsMe establishes persistence by installing itself as a Windows service disguised with legitimate-looking names, and uses a custom encrypted C2 protocol over HTTPS on port 443 to blend with normal web traffic. It collects system information, keystrokes, clipboard data, and credentials from browsers and email clients via hooking APIs such as SetWindowsHookEx. The malware employs process injection into svchost.exe and explorer.exe to evade detection, and uses a unique anti-debugging technique that checks for the presence of common sandbox tools like Process Monitor and Wireshark before executing malicious payloads. Propagation occurs through SMB brute-force attacks and exploitation of known vulnerabilities, including CVE-2021-34473 (Exchange Server ProxyShell) and CVE-2020-14871 (Oracle WebLogic).

📜 History & Notable Incidents

First observed in November 2022 targeting telecommunications and technology firms in East Asia, ManItsMe gained notoriety in March 2023 when it was linked to a breach of a major South Korean internet service provider, exfiltrating over 10 TB of customer records. In June 2023, the FBI and CISA issued a joint advisory (AA23-165A) attributing a series of attacks against U.S. academic institutions to APT41 using ManItsMe alongside other tools.

🔍 Detection Indicators

Known file hashes include SHA-256 a3f5b8c2d1e4f7a9b0c3d6e9f1a4b7c8d9e0f2a3b5c4d6e7f8a9b0c1d2e3f4 (variant from 2023-01) and 9c4e6a8b2d0f3e7a1b5c8d9f0a2e4b6c8d0f1a3b7c5e9d2f4a6b8c0e1d3f5. Behavioral signatures include outbound HTTPS connections to IPs in the 45.33.32.0/19 range, creation of the mutex "GlobalManItsMe_Session", and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunManItsMeSvc. User-Agent strings observed include "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ManItsMe/1.0".

☠️ Risk & Impact

ManItsMe poses a critical risk due to its data exfiltration capabilities, having been used to steal intellectual property, credentials, and large volumes of personally identifiable information from telecommunications and academic sectors. Financial losses from an attack on a European manufacturing firm in August 2023 were estimated at $4.7 million, according to a Dragos incident report.

🛡️ Mitigation

Mitigation includes applying Microsoft patches for Exchange Server CVE-2021-34473 and Oracle WebLogic CVE-2020-14871, enforcing SMB signing and multifactor authentication, deploying endpoint detection rules via YARA signatures matching the mutex and registry keys, and using network traffic analysis tools to flag anomalous HTTPS sessions to unknown IPs in the 45.33.32.0/19 range.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.