Matanbuchus Malware Downloader Evading AV Detections by Changing Components
ID: 0a5287ca-9128-5e46-860d-17f276252cdc
STIX ID: report--0a5287ca-9128-5e46-860d-17f276252cdc
Feed Name: cybersecurityNews.com
Threat Score
Matanbuchus has reemerged using deceptive MSI installers as loaders to deploy a modular downloader that contacts C2 (e.g., https://nady.io/check/robot.aspx) to retrieve further payloads, including ransomware; operators frequently change code, obfuscation, and MSI structures to evade antivirus and ML detections, so defenders should monitor MSI execution, unexpected spawned processes, and suspicious outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
