Tmanger

Aliases: LuckyBack

First seen
2018-06-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 12:56:29

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Tmanger, also known as LuckyBack, is a remote access trojan that provides backdoor access to compromised systems. It is used for cyber-espionage activities, primarily targeting governmental and technological sectors.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Ta428_Tmanger_Strings (yara-rule)
  • MALPEDIA_Win_Tmanger_Auto (yara-rule)

Reports & references

  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
  • ESET — Luckymouse Ta428 Compromise Able Desktop (report)
  • sentinelone.com — Thundercats Hack The Fsb Your Taxes Didnt Pay For This Op (report)
  • youtube.com — Watch (report)
  • decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
  • vblocalhost.com — Vb2020 20 (report)
  • vblocalhost.com — Vb2020 Ozawa Etal (report)
  • insight-jp.nttsecurity.com — Pandas New Arsenal Part 3 Smanager (report)
  • labs.sentinelone.com — Thundercats Hack The Fsb Your Taxes Didnt Pay For This Op (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tmanger (report)
  • insight-jp.nttsecurity.com — Pandas New Arsenal Part 1 Tmanger (report)

External references