Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 5 actors

Matanbuchus

Also known asMatanbuchus 3.0

Matanbuchus is a Windows malware loader sold as Malware-as-a-Service (MaaS), written in C++, and advertised on underground forums since February 2021 by the developer BelialDemon. It is primarily used to download and execute second-stage payloads on victim systems. Reported follow-on payloads include Cobalt Strike, Qbot/QakBot, Rhadamanthys, NetSupport RAT, and in more recent campaigns AstarionRAT. Multiple sources describe it as a premium loader with pricing ranging from about $2,500 per month for early versions to $10,000 per month for the HTTPS variant and $15,000 per month for the DNS variant of version 3.0.

Earlier reporting describes Matanbuchus as a two-stage DLL-based loader. The first stage performs environment and anti-analysis checks before loading the second stage. The second stage gathers host reconnaissance including domain, computer name, privilege level, process path, CPU and architecture details, RAM, DNS domain, and MAC address, then sends encrypted reconnaissance to command-and-control infrastructure. Documented command-and-control formats include RC4-encrypted, base64-encoded JSON in older variants and Protobuf-serialized traffic over HTTP(S) in newer variants. The malware supports a broad command set including execution of EXEs, DLLs, MSI packages, CMD and PowerShell commands, in-memory PE loading, self-update, uninstall, sleep, WMI execution, and inventory collection. Persistence has been observed via scheduled tasks, including a task named "Update Tracker Task" invoking msiexec with the uncommon -z flag.

Observed infection vectors include phishing and spear-phishing, malicious Microsoft Office macros in earlier campaigns, HTML smuggling attachments delivering ZIP archives and MSI installers, ClickFix social-engineering lures that trick users into running msiexec or PowerShell commands, and Microsoft Teams/Quick Assist-based social engineering. In one documented 2022 spam campaign, an HTML smuggling attachment masqueraded as a OneDrive-hosted scanned document and dropped an MSI signed with a revoked Westeast Tech Consulting, Corp. certificate. That MSI created C:\Users\username\AppData\Local\AdobeFontPack, dropped main.dll and notify.vbs, displayed a fake Adobe Font Pack installation/error message, and executed the DLL via regsvr32.exe using Squiblydoo-style tradecraft. The DLL used anti-debugging APIs such as IsDebuggerPresent and QueryPerformanceCounter, custom XOR-based decryption, and attempted to retrieve a Cobalt Strike Beacon from hardcoded C2 URLs including telemetrysystemcollection.com and collectiontelemetrysystem.com.

Version 3.0, observed in the wild in July 2025 and active through at least February 2026, is described as a complete rewrite. Reported capabilities include Protobuf-over-HTTPS C2, ChaCha20 encryption, MurmurHash3-based API resolution, Heaven's Gate WoW64 bypass, busy-loop sandbox evasion, hardcoded expiration dates, and enumeration of more than 70 EDR products with reporting of the victim security stack to the C2 before payload selection. It supports delivery of EXE, DLL, MSI, shellcode, PowerShell, CMD, and WMI payloads. Recent intrusion chains used dual DLL sideloading stages: first, a legitimate Zillya AVCore.exe/core.exe loading a malicious SystemStatus.dll from fake vendor-themed %APPDATA% directories such as AegisLynx Cybernetics Ltd, DocuRay Technologies S.r.l, and HelixShield Technologies ApS; second, a legitimate java.exe loading a malicious jli.dll and an encrypted Lua script (SySUpd) from a Temp directory. The malicious jli.dll was reported to unhook kernel32.dll and ntdll.dll using clean copies from \KnownDlls, initialize an embedded Lua 5.4.7 interpreter, decrypt the companion Lua script with a rolling XOR key, and execute shellcode from memory via a custom reflective loader.

Recent campaigns and reporting link Matanbuchus to ransomware-oriented and hands-on-keyboard intrusions. Huntress documented a February 2026 ClickFix intrusion in which Matanbuchus 3.0 led to deployment of AstarionRAT, followed by PsExec lateral movement, rogue account creation, and Microsoft Defender exclusion changes, with analysts assessing ransomware deployment or data exfiltration as likely objectives. ThreatLabz separately described Quick Assist-assisted delivery of a malicious MSI from gpa-cro.com, HRUpdate.exe sideloading a malicious DLL downloader, and retrieval of the main module from mechiraz.com. Mandiant reporting cited UNC4487 compromising Ukrainian government-related websites to socially engineer targets into executing Matanbuchus or CHILLYHELL, and another reference linked delivery to a Ukrainian auto insurance website. Additional reporting associated Matanbuchus use with Conti-linked activity and with a Fortgale-tracked February 2026 intrusion dubbed "FortiSync Quasar" involving Matanbuchus 3.0, Astarion RAT, and SystemBC.

High-confidence indicators mentioned in the content include hashes from the 2022 campaign such as HTML SHA256 e3b98dac9c4c57a046c50ce530c79855c9fe4025a9902d0f45b0fb0394409730, MSI SHA256 5dcbffef867b44bbb828cfb4a21c9fb1fa3404b4d8b6f4e8118c62addbf859da, and DLL SHA256 8833f28dc0cadd4b3c5676981b2a76e1c0683f2e2b8e3dac8270622c12e032ef; older C2 IPs 193.56.146.60, 193.56.146.61, 193.56.146.62, and 193.56.146.65 with gate /GtHODfM/qilZw/YjtK.php; domains telemetrysystemcollection.com and collectiontelemetrysystem.com; and version 3.0-related URLs hxxps://marle.io/check/updprofile.aspx and hxxps://mechiraz.com/cart/checkout/files/update_info.aspx. Infrastructure likely associated with Matanbuchus hosting also included treasurybanks.org, myfundsrecovery.org, maxrecovery.org, deptoftreasury.org, and usdatarecovery.org.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BelialDemon

Matanbuchus, offered as part of malware-as-a-service, has been available on underground forums for a rental price of $2500 since February 2021. Recently, the CYFIRMA research team observed this malware reappear through spam campaigns.

via cyfirma othercyfirma.com
UNC4487

According to threat intelligence shared by Google Mandiant, UNC4487 is a suspected espionage actor that has been observed compromising the websites of Ukrainian government entities to redirect and socially engineer targets to execute Matanbuchus or CHILLYHELL malware.

via the hacker newsthehackernews.com
Mora_001

The campaign, internally dubbed "FortiSync Quasar," revealed an evolution from ransomware operations to strategic espionage, deploying Matanbuchus 3.0, Astarion RAT, and SystemBC.

via blueteamsecinfosec.pub
WIZARD SPIDER

...new malware strains such as ... Matanbuchus ...

via the hacker newsthehackernews.com
GrayBravo

“uses ClickFix techniques to deliver CastleLoader and Matanbuchus”

via ctoatncsc substackctoatncsc.substack.com
MITRE ATT&CK

Techniques & procedures

37 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.001DomainsEvidence1

In this blog we will identify 6 malicious domains that are likely hosting MatanBuchus malware... Unit42 shared details of a treasurybanks[.]org domain used in malicious ads targeting users looking for funds recovery services.

T1583.008MalvertisingEvidence1

Unit42 shared details of a treasurybanks[.]org domain used in malicious ads targeting users looking for funds recovery services.

Initial Access

4 techniques
T1189Drive-by CompromiseEvidence1

UNC4487 is a suspected espionage actor that has been observed compromising the websites of Ukrainian government entities to redirect and socially engineer targets to execute Matanbuchus or CHILLYHELL malware.

T1566.001Spearphishing AttachmentEvidence1

Threat actors deliver this malicious Html file to the user through spear-phishing techniques such as the scanned document attached to the email.

T1566.002Spearphishing LinkEvidence1

Tertiary: Phishing email - traditional attachment/link delivery (historical, less common in v3.0 campaigns).

T1566.004Spearphishing VoiceEvidence1

Secondary: Microsoft Teams vishing - attacker calls via Teams impersonating IT helpdesk, convinces user to open Quick Assist, then instructs them to execute a script that downloads the loader MSI.

Execution

8 techniques
T1053.005Scheduled TaskEvidence2

The initial loader creates a working folder, where it downloads and saves the first-stage binary to use it as persistence to be run by the scheduled task... The loader doesn’t delete the scheduled task that can indicate infection by Matanbuchus.

T1059.001PowerShellEvidence2
TacticExecution

The loader can also run a PS command using the same technique. It creates an instance of powershell.exe with the attacker’s command line.

T1059.003Windows Command ShellEvidence1
TacticExecution

The loader can also act like a bot and run CMD commands... creates an instance of cmd.exe with the extracted command line, e.g., C:\\Windows\\System32\\cmd.exe /c <cmd_from_c2>.

T1059.007JavaScriptEvidence1
TacticExecution

This malware sample was written in a combination of Html and JavaScript language... the Threat actor embedded the malicious zip file in the JavaScript in base64 format.

T1106Native APIEvidence1
TacticExecution

"walking the Process Environment Block to locate ntdll.dll and resolve four native API functions by hash"; "All API access is routed through an internal hash dispatch function"

T1129Shared ModulesEvidence1
TacticExecution

The executed routine will be one of the exported functions of the DLL... each command will load the DLL to memory and run another exported function of the downloaded payload, DllRegisterServer or DllInstall.

T1204User ExecutionEvidence1
TacticExecution

UNC4487 is a suspected espionage actor that has been observed compromising the websites of Ukrainian government entities to redirect and socially engineer targets to execute Matanbuchus or CHILLYHELL malware.

T1204.002Malicious FileEvidence2
TacticExecution

Once the user clicks that attached file, this Html drops the zip file in the Downloader folder... Upon execution of this MSI file, it shows the fake Adobe error message to the user while dropping the malicious dll file in the background.

Persistence

2 techniques
T1053.005Scheduled TaskEvidence2

The initial loader creates a working folder, where it downloads and saves the first-stage binary to use it as persistence to be run by the scheduled task... The loader doesn’t delete the scheduled task that can indicate infection by Matanbuchus.

T1136.002Domain AccountEvidence1

Created rogue domain accounts ... net user <rogue_account> <password> /add /domain

T1053.005Scheduled TaskEvidence2

The initial loader creates a working folder, where it downloads and saves the first-stage binary to use it as persistence to be run by the scheduled task... The loader doesn’t delete the scheduled task that can indicate infection by Matanbuchus.

T1548.002Bypass User Account ControlEvidence1

Matanbuchus downloads the payload and calls ShellExecuteExA... sets the lpVerb member to runas. This method will execute a given process with admin privileges.

Stealth

9 techniques
T1027Obfuscated Files or InformationEvidence2
TacticStealth

The second stage is also obfuscated. Here, the strings are encrypted and obfuscated using different techniques of stack strings, and they are dynamically decrypted... most of the API calls are obfuscated... resolved dynamically... comparing the function names to the given fnv1a hash.

T1036MasqueradingEvidence1
TacticStealth

"...drops a legitimate but vulnerable Zillya Antivirus binary alongside a malicious DLL into deceptive directories mimicking fake vendors like “AegisLynx” or “DocuRay”."

T1218.007MsiexecEvidence3
TacticStealth

After extraction, the dropped zip file is found to contain an MSI installer file... Upon execution of this MSI file... In the background, the MSI file creates the AdobeFontPack folder... followed by dropping two files – dll[main.dll] file and vbs[notify.vbs] file.

T1218.010Regsvr32Evidence2
TacticStealth

This MSI file loads this malicious dll file[ main.dll] through regsvr32.exe with arguments being -n -i “install”.

T1218.011Rundll32Evidence1
TacticStealth

The loader executes DLLs by using the classic binary, Rundll32.exe... uses CreateProcessA to run rundll32.exe, which will run the final payload.

T1497Virtualization/Sandbox EvasionEvidence1

If this path exists, the malware will exit, which might be quite an odd check. We assume that this check tends to be an anti-sandbox trick for known and popular online sandbox services like Any.Run.

T1497.001System ChecksEvidence3

This dll having anti-debugging capabilty ,this dll file is checking presences for any debugger by calling APIs such as IsProcessorFeaturePresent(),IsDebuggerPresent(), QueryPerformanceCounter().

T1497.003Time Based ChecksEvidence1

This dll having anti-debugging capabilty ,this dll file is checking presences for any debugger by calling APIs such as IsProcessorFeaturePresent(),IsDebuggerPresent(), QueryPerformanceCounter().

T1620Reflective Code LoadingEvidence3
TacticStealth

Run PE within memory... saves the binary only within memory... creates a new thread that runs the MemLoad function... loads it into memory, relocates it to a proper address, and then executes it from the entry point of the PE file.

Discovery

8 techniques
T1016System Network Configuration DiscoveryEvidence1
TacticDiscovery

The last part of the victim’s reconnaissance is to get the computer’s MAC address... calling... GetAdaptersInfo... holds the MAC address... The loader gets the name of the DNS domain of the local machine... reads the victim logon server’s name.

T1033System Owner/User DiscoveryEvidence1
TacticDiscovery

The loader first retrieves the network domain name associated with the victim user by calling ExpandEnvironmentStringsA with the environment variable of %USERDOMAIN%.

T1069Permission Groups DiscoveryEvidence1
TacticDiscovery

Matanbuchus uses a known technique to check whether the running process is running with administrator privileges... calls CheckTokenMembership with the created SID of the administrator group.

T1082System Information DiscoveryEvidence1
TacticDiscovery

The loader gathers information about the compromised machine to send to the C2 server... retrieves the network domain name... computer name... checks the privileges... gets the full path of the process... collects basic CPU information... checks if the machine architecture is 32-bit or 64-bit... gets the number of processors... reads the victim logon server’s name... gets the RAM size... gets the name of the DNS domain of the local machine.

T1497Virtualization/Sandbox EvasionEvidence1

If this path exists, the malware will exit, which might be quite an odd check. We assume that this check tends to be an anti-sandbox trick for known and popular online sandbox services like Any.Run.

T1497.001System ChecksEvidence3

This dll having anti-debugging capabilty ,this dll file is checking presences for any debugger by calling APIs such as IsProcessorFeaturePresent(),IsDebuggerPresent(), QueryPerformanceCounter().

T1497.003Time Based ChecksEvidence1

This dll having anti-debugging capabilty ,this dll file is checking presences for any debugger by calling APIs such as IsProcessorFeaturePresent(),IsDebuggerPresent(), QueryPerformanceCounter().

T1518.001Security Software DiscoveryEvidence1
TacticDiscovery

Step 5 - C2 Registration + EDR Enumeration T1071.001, T1518.001 | Malware Main module registers with C2 via Protobuf-over-HTTPS ... Transmits: hostname, username, Windows version, domain, installed EDR products

Lateral Movement

2 techniques
T1021.002SMB/Windows Admin SharesEvidence1

Step 8 - Lateral Movement (Operator) T1021.002, T1570 | Operator Next-day return. PsExec to Windows Server → DC1 → DC2 in ~40 minutes.

T1570Lateral Tool TransferEvidence1

Step 8 - Lateral Movement (Operator) T1021.002, T1570 | Operator Next-day return. PsExec to Windows Server → DC1 → DC2 in ~40 minutes.

T1001Data ObfuscationEvidence1

The data sent to the C2 server is a base64 string of JSON data... JSON values are encrypted and then encoded with base64... The value for each key is encrypted with RC4 encryption and later encoded with base64.

T1071.001Web ProtocolsEvidence3

This malicious dll file is establishing a connection to the C&C server for download and trying to download another malware which is Cobalt Strike beacon payload.

T1105Ingress Tool TransferEvidence1

Matanbuchus mainly downloads and executes different payloads like Qbot and Cobalt Strike beacons... It downloads the attacker’s payload from the given URL, saves it to the disk and executes it... the loader can download the attacker’s payload from any remote server like free hosting services.

T1132.001Standard EncodingEvidence1

The Threat actor embedded the malicious zip file in the JavaScript in base64 format... Threat actors use a customized decryption method to decrypt the malicious code... using a combination of two key pairs to generate one XOR key for decrypting the encrypted contents.

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

Created rogue domain accounts. Staged Defender exclusions ( Set-MpPreference -ExclusionPath ).

INDICATORS OF COMPROMISE

IOCs tracked for this family

185 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
41 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
33 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
111 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app27 days ago
domain●●●●●●●●●●●●View more in app2 months ago
uri●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
uri●●●●●●●●●●●●View more in app2 months ago
uri●●●●●●●●●●●●View more in app2 months ago
ACTIVITY FEED

Recent activity

32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

shroudcloudNews
Apr 14, 2026
Matanbuchus - ShroudCloud

A premium C++ malware loader sold as MaaS that performs adaptive payload delivery by enumerating installed EDR products, reporting them to C2, and allowing operators to choose execution methods accordingly. It supports multiple payload formats, uses Protobuf-over-HTTPS with ChaCha20 encryption, employs Heaven's Gate and DLL sideloading for evasion, and has delivered RATs, stealers, Cobalt Strike, and unspecified ransomware.

Read more
the hacker newsNews
Feb 20, 2026
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT RAT

Loader used in a related ClickFix campaign to deliver MIMICRAT.

Read more
the hacker newsNews
Feb 19, 2026
ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws & 20+ Stories

Malware-as-a-service loader delivered via ClickFix campaigns; used as a foothold to rapidly progress to lateral movement and domain controller access, with the stated objective to deploy ransomware or exfiltrate data.

Read more
cyber security newsNews
Feb 18, 2026
Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT

A premium MaaS loader used for high-value targeted intrusions. In this campaign it is delivered via the ClickFix social-engineering technique (users tricked into running PowerShell/Run commands), then uses an msiexec-based chain with DLL sideloading (via a legitimate but vulnerable Zillya Antivirus binary) and staged extraction/decryption to ultimately execute the next-stage payload in memory.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching185

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping37

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.