logo

Matanbuchus Malware Evolves to Bypass AV Defenses by Swapping Core Components

ID: a28d143e-326f-565b-9191-55deafe25f7b

STIX ID: report--a28d143e-326f-565b-9191-55deafe25f7b

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Matanbuchus is a C++ downloader/backdoor Malware-as-a-Service that has matured into a flexible initial access and control platform frequently used to stage ransomware and other secondary payloads. Version 3.0 adds stronger obfuscation (ChaCha20-encrypted strings, MurmurHash-based API resolution), Protobuf C2 messages, and a downloader/main module architecture; recent attacks abused Microsoft Quick Assist and MSI DLL sideloading to deploy the loader, and the report includes multiple SHA256 hashes and malicious domains as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.