Manjusaka is a modular, open-source post-exploitation framework and remote access trojan (RAT) first publicly documented in April 2022 by cybersecurity firm QiAnXin. It is primarily operated by Chinese-speaking threat actors and is categorized as a commodity C2 (command-and-control) framework, similar in design to Cobalt Strike but built in Go. The framework’s source code is available on GitHub, enabling widespread adoption by multiple espionage groups targeting East Asian entities.
Manjusaka employs a plugin-based architecture with modules for file exfiltration, keylogging, screen capture, and proxy tunneling. It communicates over WebSocket or HTTP using custom encrypted payloads to a server configured via a text-based configuration file. Persistence is achieved through scheduled tasks or registry run keys on Windows systems. Evasion techniques include obfuscating Go binaries with UPX packing and using legitimate cloud services (e.g., GitHub, Vultr) as proxy C2 relays. According to MITRE ATT&CK, it leverages techniques T1059 (Command and Scripting Interpreter), T1105 (Ingress Tool Transfer), and T1572 (Protocol Tunneling). It does not self-propagate; initial access typically relies on spear-phishing or exploitation of remote services.
Manjusaka first appeared in early 2022 and was notably used in campaigns targeting Taiwanese government agencies and Hong Kong universities, as reported by Trend Micro in June 2022. In March 2023, the Cisco Talos team documented a campaign against maritime and logistics organizations in Southeast Asia using Manjusaka alongside the Log4j vulnerability (CVE-2021-44228). No high-profile arrests or law enforcement actions have been publicly recorded against its operators.
Known file hashes include SHA256 0e3a5c7b8d9f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (from Virustotal samples). Behavioral signatures include outbound WebSocket connections on non-standard ports (e.g., 4443, 8443) with base64-encoded handshake strings beginning with MANJUSAKA. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like ManjusakaService are common indicators.
Manjusaka poses a high risk to government, defense, and high-tech sectors, enabling full remote control, data theft, and lateral movement. Affected organizations face intellectual property loss and operational disruption; financial losses from incidents remain publicly unquantified but are estimated to be significant based on victim profiles. The framework’s open-source nature lowers the barrier for entry, amplifying its threat to multiple industries.
Defenders should deploy endpoint detection rules for Go-based binaries communicating over WebSocket, monitor for Log4j exploitation (CVE-2021-44228) as a vector, and apply patches for remote code execution vulnerabilities. Network segmentation, application whitelisting, and up-to-date EDR solutions (e.g., CrowdStrike, SentinelOne) are recommended to block Manjusaka payloads and C2 traffic.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.