Skip to content

Matanbuchus

Matanbuchus is a Windows malware-as-a-service loader first publicly identified in 2021 and marketed on Russian-speaking cybercrime forums.

Profile source: Mallory opens in a new tab

Matanbuchus

Family profile

Matanbuchus is a Windows malware-as-a-service loader first publicly identified in 2021 and marketed on Russian-speaking cybercrime forums. It is commonly described as a commercial two-stage loader used to retrieve and execute follow-on payloads on compromised systems, including QakBot and Cobalt Strike, and has also been associated with broader cybercrime delivery ecosystems. The service has been linked to the actor known as BelialDemon.

Matanbuchus is designed for stealthy payload delivery and post-compromise tasking. Reported capabilities include downloading and launching additional malware, executing DLLs and executables, running arbitrary shell and PowerShell commands, loading shellcode, and manually mapping payloads directly into memory. Multiple analyses describe obfuscated string handling, dynamic API resolution using FNV-1a hashing, anti-analysis and anti-sandbox checks, and encrypted command-and-control communications using base64-encoded JSON with RC4-encrypted values. Some variants establish persistence through scheduled tasks that repeatedly invoke trusted Windows utilities to execute the loader or updated components.

Observed infection chains show Matanbuchus delivered through phishing and malspam, often using ZIP archives, HTML smuggling, and malicious MSI installers masquerading as legitimate software or updates. It has also been observed in ClickFix-style social-engineering chains in which victims are tricked into executing malicious commands that lead to MSI or script-based installation. MSI-based deployments commonly use asynchronous custom actions, fake error dialogs, and trusted Windows binaries such as regsvr32 to launch the loader while misleading the user.

Matanbuchus has been used as an access-enabling component in multi-stage intrusions and criminal operations. It has appeared in campaigns that culminated in Cobalt Strike deployment, and later-stage activity has included delivery of remote-access tools and other malware families. Reporting also places it within ecosystems that use crypters and loaders to evade detection and broker access between initial infection and downstream monetization. The malware primarily targets Windows environments and has been observed against organizations in sectors including education and technology, while also appearing in broad spam-driven campaigns without narrow sector specialization.

Capabilities

  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation

Reported operators

Threat actors

6 named in public reporting
BelialDemon

Beginning in May 2024, and carrying into early June, eSentire has identified an increase in observations of Matanbuchus malware. Matanbuchus is a loader type malware that was first identified in 2021.

TA571

If the “Auto-fix” button was clicked, the search-ms protocol displayed a similar WebDAV-hosted “fix.msi” or “fix.vbs” in Windows Explorer... This led to the installation of Matanbuchus.

UNC4487

According to threat intelligence shared by Google Mandiant, UNC4487 is a suspected espionage actor that has been observed compromising the websites of Ukrainian government entities to redirect and socially engineer targets to execute Matanbuchus or CHILLYHELL malware.

Mora_001

The campaign, internally dubbed "FortiSync Quasar," revealed an evolution from ransomware operations to strategic espionage, deploying Matanbuchus 3.0, Astarion RAT, and SystemBC.

TAG-150

“uses ClickFix techniques to deliver CastleLoader and Matanbuchus”

MITRE ATT&CK

Matanbuchus in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1218.007 Msiexec T1583 Acquire Infrastructure T1036 Masquerading T1189 Drive-by Compromise T1059.007 JavaScript T1560 Archive Collected Data T1059 Command and Scripting Interpreter T1027 Obfuscated Files or Information T1218.010 Regsvr32 T1082 System Information Discovery T1140 Deobfuscate/Decode Files or Information T1497.001 System Checks T1129 Shared Modules T1027.007 Dynamic API Resolution T1071 Application Layer Protocol T1566 Phishing T1053 Scheduled Task/Job T1497.003 Time Based Checks T1620 Reflective Code Loading T1105 Ingress Tool Transfer T1566.001 Spearphishing Attachment T1204 User Execution T1497 Virtualization/Sandbox Evasion T1021 Remote Services T1053.005 Scheduled Task T1033 System Owner/User Discovery T1059.001 PowerShell T1583.001 Domains T1059.005 Visual Basic T1059.003 Windows Command Shell T1571 Non-Standard Port T1573.001 Symmetric Cryptography T1204.002 Malicious File T1115 Clipboard Data T1218 System Binary Proxy Execution T1071.001 Web Protocols T1132.001 Standard Encoding T1548.002 Bypass User Account Control T1001 Data Obfuscation T1016 System Network Configuration Discovery T1218.011 Rundll32 T1069 Permission Groups Discovery T1566.004 Spearphishing Voice T1021.002 SMB/Windows Admin Shares T1562.001 Disable or Modify Tools T1518.001 Security Software Discovery T1566.002 Spearphishing Link T1570 Lateral Tool Transfer T1136.002 Domain Account T1583.008 Malvertising T1106 Native API T1059.006 Python T1560.001 Archive via Utility T1057 Process Discovery T1518 Software Discovery T1055 Process Injection T1136 Create Account

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.