Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mana Team

Also known as: Mana Team

Description

**Targets:** Australia **Notes:** iSight has mentioned tracking a China-nexus activity they dub "Mana Team", targeting Australian interests - have not resolved this w/ other naming conventions

Goals & Targeting

Targeted Countries / Regions

CN

AI Analysis

· 1 week ago

Executive Summary

Mana Team is a suspected nation-state cyber threat actor primarily involved in espionage activities targeting Australian interests. The group's operations suggest a high level of sophistication, potentially aligned with Chinese geopolitical objectives. Mana Team has demonstrated the capability to infiltrate critical sectors through targeted campaigns, employing advanced tactics such as phishing and credential dumping.

Goals & Targeting

Mana Team's strategic objectives appear to be centered around espionage, with a focus on collecting intelligence from sectors that align with geopolitical interests in Australia. The targeting of government agencies, educational institutions, and research organizations suggests an intent to gather sensitive data related to national security, defense capabilities, and technological advancements. The group's geographic focus on Australia indicates a potential alignment with nation-state interests aimed at monitoring or influencing the region.

Enhanced Description

Mana Team is a cyber threat actor tracked by iSight as being associated with China-nexus activity, though its exact origin remains unconfirmed. The group's primary focus appears to be targeting Australian government, education, and research sectors through sophisticated espionage campaigns. While no definitive nation-state affiliation has been established, the level of operational sophistication and targeting patterns align with advanced persistent threat (APT) groups typically associated with state-sponsored actors. Mana Team's tactics involve initial access via phishing emails containing malicious attachments, followed by credential harvesting and lateral movement within targeted networks. The group's activities suggest a long-term goal of gathering sensitive political, economic, and defense-related information from Australian entities.

Key Capabilities

  • Spear-phishing campaigns using malicious attachments
  • Credential dumping via Windows Registry manipulation
  • Lateral movement within compromised networks
  • Persistence techniques including DNS-based command and control (C2)
  • High-level operational tradecraft indicative of APT groups

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Defense Evasion
Credential Access

ATT&CK Techniques

T1567.001 -Credential Dumping: Windows Registry
T1569.003 - OS Credential Access: Built-in Credentials
T1189 - Phishing for creds via malicious links
T1566.003 - Internal Spear-Phishing via Attachments

Software / Tooling

Custom malware for credential extraction
Lateral movement tools
Persistence mechanisms

Campaigns & Victims

Mana Team's campaigns have been observed targeting Australian entities since at least [first seen date]. The group employs persistent and patient attack techniques, suggesting long-term interests in maintaining access to targeted networks. Notable operations include the use of spear-phishing emails containing malicious Office documents and subsequent deployment of custom malware for data collection. The group has demonstrated a focus on low-profile operations, likely to avoid detection while achieving its espionage objectives.

IOC Patterns

  • Spear-phishing emails with malicious attachments targeting Australian entities
  • DNS queries for domain generation (potential C2)
  • Unusual network traffic patterns in education and government sectors
  • Account credentials being exfiltrated via encrypted channels

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts
  • Monitor for unusual login patterns and credential dumping activities
  • Conduct regular cybersecurity awareness training for employees
  • Segment sensitive networks and implement strict access controls
  • Use endpoint detection and response (EDR) solutions to identify malicious processes

Suggested Tags

APT
espionage
China-nexus
Australia-targeted
nation-state

Confidence Assessment

High confidence in the nation-state affiliation due to targeting patterns and operational methodology. Limited visibility into specific tools and techniques used by Mana Team remains a gap.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
espionage
China-nexus
Australia-targeted
nation-state

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.