Manager APT Toolkit
First observed in late 2019, the Manager toolkit is a set of three C++ based tools; NewManager, AmpManager, and DDoSManager, created by the ChinaZ advanced persistent threat to primarily target Linux web servers.
Summary
First observed in late 2019, the Manager toolkit is a set of three C++ based tools; NewManager, AmpManager, and DDoSManager, created by the ChinaZ advanced persistent threat to primarily target Linux web servers.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication it is unclear how the toolkit is delivered however, there are unconfirmed reports that ChinaZ has been observed deploying malware compromised with Manager binaries.
Each of the three tools contains its own persistence and command mechanisms and as such can be launched individually. The tools are listed bellow:
- NewManager - A backdoor used to collect system and user information, before connecting to a command and control server.
- AmpManager - Similar functionality to NewManager, but is able to perform DNS, NTP, and SSDP flood distributed denial-of-service (DDoS) attacks.
- DDoSManager - Uses a different code base, but has similar functionality and persistence methods as AmpManager. Able to perform SYN, UDP, and DNS flood DDoS attacks.
Remediation steps
| Type | Step |
|---|---|
|
To protect against a distributed denial-of-service (DDoS) attack, organisations should ensure:
Should an organisation suspect it is subject to an active DDoS attack, they should ensure that every effort is made to stop the attack and restore service. However, care should be taken to ensure that the attackers are not using the DDoS attack as a distraction whilst other, potentially more sensitive, systems are exploited. Monitoring of critical systems is recommended, including the use of host-based intrusion prevention and detection systems (HIPS/HIDS) where appropriate. Additionally, to prevent and detect an infection, ensure that:
|
Last edited: 29 June 2021 11:57 am