Elite 'Matanbuchus 3.0' Loader Spruces Up Ransomware Infections
ID: 6fdd46d4-6ae2-5beb-a62d-e1774fb73dc0
STIX ID: report--6fdd46d4-6ae2-5beb-a62d-e1774fb73dc0
Feed Name: Dark Reading
Threat Score
Researchers observed the Matanbuchus 3.0 malware-as-a-service loader being distributed via active spear-phishing and IT help-desk social engineering (e.g., Microsoft Teams/Quick Assist) to deliver ransomware and other secondary payloads against real estate, finance, and other companies in the US and Europe; Matanbuchus 3.0 includes sophisticated EDR/XDR evasion, in-memory stealth, DNS/HTTPS C2 options, dynamic obfuscation, and techniques to establish stealthy persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
