Tmanger
Aliases: LuckyBack
- First seen
- 2018-06-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:56:29
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Tmanger, also known as LuckyBack, is a remote access trojan that provides backdoor access to compromised systems. It is used for cyber-espionage activities, primarily targeting governmental and technological sectors.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Apt_Ta428_Tmanger_Strings (yara-rule)
- MALPEDIA_Win_Tmanger_Auto (yara-rule)
Reports & references
- decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
- ESET — Luckymouse Ta428 Compromise Able Desktop (report)
- sentinelone.com — Thundercats Hack The Fsb Your Taxes Didnt Pay For This Op (report)
- youtube.com — Watch (report)
- decoded.avast.io — Apt Group Targeting Governmental Agencies In East Asia (report)
- vblocalhost.com — Vb2020 20 (report)
- vblocalhost.com — Vb2020 Ozawa Etal (report)
- insight-jp.nttsecurity.com — Pandas New Arsenal Part 3 Smanager (report)
- labs.sentinelone.com — Thundercats Hack The Fsb Your Taxes Didnt Pay For This Op (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tmanger (report)
- insight-jp.nttsecurity.com — Pandas New Arsenal Part 1 Tmanger (report)