BelialDemon
BelialDemon is the threat actor name associated in the provided reporting with Matanbuchus, a Malware-as-a-Service loader first advertised on Russian-speaking cybercrime forums in February 2021. The content identifies BelialDemon as the actor behind Matanbuchus advertising and notes CYFIRMA attributed a 2022 Matanbuchus spam and spear-phishing campaign to BelialDemon. In the reported 2022 activity, the infection chain used phishing or spear-phishing emails carrying a malicious HTML attachment that performed HTML smuggling to drop a ZIP archive containing an MSI installer. The lure impersonated a OneDrive-hosted scanned document. The MSI was signed with a revoked certificate, displayed a fake Adobe Font Pack installation and error message, dropped a DLL and VBS script into the victim AppData path, and executed the DLL via regsvr32.exe in Squiblydoo-style fashion. The Matanbuchus DLL used anti-debugging checks, custom XOR-based decryption, and attempted to contact multiple command-and-control URLs to retrieve an additional payload identified by CYFIRMA as Cobalt Strike Beacon. The content also states that Matanbuchus has been used to deliver follow-on payloads including Cobalt Strike, QakBot, DanaBot, Rhadamanthys stealer, and NetSupport RAT. Huntress describes Matanbuchus 3.0 as a complete rewrite with higher-priced HTTPS and DNS variants, anti-analysis protections including junk code and dead loops, ChaCha20-encrypted strings and shellcode handling, process enumeration for security-product discovery, and the ability to run multiple payload formats from disk or memory. In a 2026 intrusion discussed in the content, Matanbuchus 3.0 was delivered via ClickFix social engineering and ultimately deployed a custom implant Huntress named AstarionRAT; the intrusion included rapid lateral movement with PsExec, rogue account creation, and Microsoft Defender exclusion staging. Aliases directly supported by the content: belialdemon.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertised and sold the Matanbuchus MaaS loader on Russian-speaking cybercrime forums (initially in 2021), positioning it as a premium loader used for high-value, targeted intrusions that can deliver follow-on payloads (e.g., Cobalt Strike, QakBot, DanaBot, Rhadamanthys, NetSupport RAT).
Attributed with distributing the Matanbuchus malware loader via spam and spear-phishing campaigns using HTML smuggling, MSI installers, and regsvr32 to load a malicious DLL that attempts to download additional payloads including a Cobalt Strike beacon.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.