logo

Elite 'Matanbuchus 3.0' Loader Spruces Up Ransomware Infections

ID: 6fdd46d4-6ae2-5beb-a62d-e1774fb73dc0

STIX ID: report--6fdd46d4-6ae2-5beb-a62d-e1774fb73dc0

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-07-16

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers observed the Matanbuchus 3.0 malware-as-a-service loader being distributed via active spear-phishing and IT help-desk social engineering (e.g., Microsoft Teams/Quick Assist) to deliver ransomware and other secondary payloads against real estate, finance, and other companies in the US and Europe; Matanbuchus 3.0 includes sophisticated EDR/XDR evasion, in-memory stealth, DNS/HTTPS C2 options, dynamic obfuscation, and techniques to establish stealthy persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.