Researchers have identified a new post-exploitation attack framework used by hackers, called Manjusaka, which can be deployed as an alternative to the widely used Cobalt Strike toolkit or in parallel for redundancy.

Manjusaka uses implants written in the Rust programming language on multiple platforms, while its binaries are written in GoLang.
RAT (remote access trojan) implants support command execution, file access, network reconnaissance , and more, so hackers can use it for the same operational goals as Cobalt Strike.
See also: VMware to admins: Fix critical auth bypass bug immediately
Expedition and discovery
Manjusaka was discovered by researchers at Cisco Talos, who were called in to investigate a Cobalt Strike infection on a customer, so the threat actors used both frameworks in that case.
The infection originated through a malicious document disguised as a report of a COVID-19 case in the city of Golmud in Tibet for contact tracing.
The document presented a VBA macro that is executed via rundll32.exe to retrieve a second-stage payload, Cobalt Strike, and load it into memory.
See also: How malware tricks users and antivirus programs
However, instead of simply using Cobalt Strike as the main attack toolkit, they used it to download the Manjusaka implants, which depending on the host architecture, can be EXE (Windows) or ELF (Linux) files.
Manjusaka's capabilities
Both versions of the implant for Windows and Linux have almost the same features and implement similar communication mechanisms.
The implants include a RAT and a file management module, each of which has distinct capabilities.
The RAT supports arbitrary command execution via “cmd.exe”, collects credentials stored in web browsers, WiFi SSIDs and passwords , and discovers network connections (TCP and UDP), account names, etc.
Furthermore, it can steal Premiumsoft Navicat credentials, take screenshots of the current desktop, list running processes, and even check hardware specs and thermal characteristics.
See also: Solana wallets breached in multi-million dollar hack
The file management module can perform file enumeration, create directories, obtain full file paths, read or write file contents , delete files or directories, and move files between locations.

At this time, it appears that Manjusaka has been temporarily deployed for testing, so its development is likely not in its final stages. However, the new framework is already powerful enough for real-world use.
Cisco notes that its researchers found a promotional post in an advertising post from the malware author, depicting components that were not implemented in the sample versions.
This means that they are not available in the “free” version used in the analyzed attack or have not yet been completed by the author.
Information source: bleeoingcomputer.com
