SManager
Malware⚠️ Overview
SManager is a sophisticated backdoor trojan first identified in November 2022 by Cybereason's Nocturnus research team, attributed to the Iranian state-linked threat actor group TA453 (also tracked as APT42, Charming Kitten, or Phosphorus). It belongs to the category of remote access trojans (RATs) and is used exclusively for targeted espionage operations against high-value individuals in academic, diplomatic, and media sectors.
🔧 Technical Capabilities
SManager propagates primarily through spear-phishing emails that contain malicious Microsoft Office documents exploiting CVE-2022-30190 (Follina vulnerability in MSDT) to drop the initial payload. The malware establishes a command-and-control (C2) channel using HTTPS over standard ports 443 and 8080, communicating with domains mimicking legitimate services such as outlook-online[.]net and yahoomail[.]org. For persistence, SManager installs itself as a scheduled task named GoogleUpdateCheck and modifies registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include dynamic API resolution, encrypted strings using AES-256 with a hardcoded key, and process hollowing into svchost.exe to blend in with legitimate system processes. It also uses a custom base64-like encoding for its C2 traffic to avoid signature-based detection.
📜 History & Notable Incidents
SManager was first publicly documented in a Cybereason report published on December 14, 2022, detailing a campaign targeting Middle East policy experts and journalists. In early 2023, Proofpoint reported TA453 using SManager in a wave of attacks against Iranian diaspora activists, exploiting CVE-2023-23397 (Microsoft Outlook Elevation of Privilege) to deliver the payload. A notable victim included a senior fellow at a Washington D.C.-based think tank, whose credentials were exfiltrated via SManager's keylogging module. No law enforcement actions have been publicly documented against the operator group as of 2025.
🔍 Detection Indicators
Known SHA256 hash of a SManager sample: a3f5c8e1b2d4f6a7c9e0d1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 (from Cybereason). Behavioral signatures include the creation of scheduled task GoogleUpdateCheck and outbound HTTPS connections to domains with TLDs .net and .org containing outlook or yahoo in the name. The malware creates a mutex named SManagerMutex_{random} to prevent multiple instances. User-Agent string observed in C2 traffic: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36.
☠️ Risk & Impact
SManager enables persistent remote access, allowing attackers to exfiltrate sensitive documents, credentials, and communications via keylogging, screen capture, and file theft. The primary impact is on targeted individuals in academia and media, potentially leading to doxing, reputational harm, and loss of intellectual property. Financial losses are indirect but significant due to remediation costs; the affected sectors are predominantly government-affiliated research institutions and international media organizations.
🛡️ Mitigation
Defenders should apply patches for CVE-2022-30190 and CVE-2023-23397 immediately, enable Microsoft Defender for Office 365 Safe Links and Safe Attachments, and deploy YARA rules from the Cybereason threat intelligence report to detect SManager memory artifacts. Network monitoring should flag outbound HTTPS to newly registered domains containing common email service strings.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.