Matanbuchus Malware Evolves to Bypass AV Defenses by Swapping Core Components
ID: a28d143e-326f-565b-9191-55deafe25f7b
STIX ID: report--a28d143e-326f-565b-9191-55deafe25f7b
Feed Name: GBHackers
Matanbuchus is a C++ downloader/backdoor Malware-as-a-Service that has matured into a flexible initial access and control platform frequently used to stage ransomware and other secondary payloads. Version 3.0 adds stronger obfuscation (ChaCha20-encrypted strings, MurmurHash-based API resolution), Protobuf C2 messages, and a downloader/main module architecture; recent attacks abused Microsoft Quick Assist and MSI DLL sideloading to deploy the loader, and the report includes multiple SHA256 hashes and malicious domains as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
