Beginning in May 2024, and carrying into early June, eSentire has identified an increase in observations of Matanbuchus malware. Matanbuchus is a loader type malware that was first identified in 2021.
Matanbuchus
Matanbuchus is a Windows malware-as-a-service loader first publicly identified in 2021 and marketed on Russian-speaking cybercrime forums.
Profile source: Mallory opens in a new tabMatanbuchus
Family profile
Matanbuchus is a Windows malware-as-a-service loader first publicly identified in 2021 and marketed on Russian-speaking cybercrime forums. It is commonly described as a commercial two-stage loader used to retrieve and execute follow-on payloads on compromised systems, including QakBot and Cobalt Strike, and has also been associated with broader cybercrime delivery ecosystems. The service has been linked to the actor known as BelialDemon.
Matanbuchus is designed for stealthy payload delivery and post-compromise tasking. Reported capabilities include downloading and launching additional malware, executing DLLs and executables, running arbitrary shell and PowerShell commands, loading shellcode, and manually mapping payloads directly into memory. Multiple analyses describe obfuscated string handling, dynamic API resolution using FNV-1a hashing, anti-analysis and anti-sandbox checks, and encrypted command-and-control communications using base64-encoded JSON with RC4-encrypted values. Some variants establish persistence through scheduled tasks that repeatedly invoke trusted Windows utilities to execute the loader or updated components.
Observed infection chains show Matanbuchus delivered through phishing and malspam, often using ZIP archives, HTML smuggling, and malicious MSI installers masquerading as legitimate software or updates. It has also been observed in ClickFix-style social-engineering chains in which victims are tricked into executing malicious commands that lead to MSI or script-based installation. MSI-based deployments commonly use asynchronous custom actions, fake error dialogs, and trusted Windows binaries such as regsvr32 to launch the loader while misleading the user.
Matanbuchus has been used as an access-enabling component in multi-stage intrusions and criminal operations. It has appeared in campaigns that culminated in Cobalt Strike deployment, and later-stage activity has included delivery of remote-access tools and other malware families. Reporting also places it within ecosystems that use crypters and loaders to evade detection and broker access between initial infection and downstream monetization. The malware primarily targets Windows environments and has been observed against organizations in sectors including education and technology, while also appearing in broad spam-driven campaigns without narrow sector specialization.
Capabilities
- Defense Evasion
- Initial Access
- Persistence
- Post Exploitation
Reported operators
Threat actors
6 named in public reportingIf the “Auto-fix” button was clicked, the search-ms protocol displayed a similar WebDAV-hosted “fix.msi” or “fix.vbs” in Windows Explorer... This led to the installation of Matanbuchus.
According to threat intelligence shared by Google Mandiant, UNC4487 is a suspected espionage actor that has been observed compromising the websites of Ukrainian government entities to redirect and socially engineer targets to execute Matanbuchus or CHILLYHELL malware.
The campaign, internally dubbed "FortiSync Quasar," revealed an evolution from ransomware operations to strategic espionage, deploying Matanbuchus 3.0, Astarion RAT, and SystemBC.
...new malware strains such as ... Matanbuchus ...
“uses ClickFix techniques to deliver CastleLoader and Matanbuchus”
MITRE ATT&CK