logo

Matanbuchus Malware Downloader Evading AV Detections by Changing Components

ID: 0a5287ca-9128-5e46-860d-17f276252cdc

STIX ID: report--0a5287ca-9128-5e46-860d-17f276252cdc

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Matanbuchus has reemerged using deceptive MSI installers as loaders to deploy a modular downloader that contacts C2 (e.g., https://nady.io/check/robot.aspx) to retrieve further payloads, including ransomware; operators frequently change code, obfuscation, and MSI structures to evade antivirus and ML detections, so defenders should monitor MSI execution, unexpected spawned processes, and suspicious outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.