From a Teams Call to a Ransomware Threat: Matanbuchus 3.0 MaaS Levels Up
ID: 830107b5-3387-56e0-81ee-3c808f0adffc
STIX ID: report--830107b5-3387-56e0-81ee-3c808f0adffc
Feed Name: Morphisec Blog
This report analyzes Matanbuchus 3.0, a commercially offered malware loader used since 2021 and updated in 2025, describing targeted delivery (Notepad++ updater sideloading via convincing social engineering), robust persistence (COM-based scheduled tasks using regsvr32 -i), multiple next-stage execution methods (MSI, process hollowing, regsvr32/rundll32, cmd/PowerShell/WQL), advanced evasion and in-memory techniques (Salsa20 obfuscation, MurmurHash3 API resolution, indirect syscalls, EDR detection checks), C2 behavior (HTTPS impersonating Skype user-agent), and a list of IOCs and file hashes observed in active campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
