logo

Technical Analysis of Matanbuchus 3.0

ID: 028b888c-8306-5f2a-9f0d-e42d15f3913c

STIX ID: report--028b888c-8306-5f2a-9f0d-e42d15f3913c

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-12-02

Date Updated: 2026-05-01

...
...

This technical analysis details the Matanbuchus malware family: initial access via QuickAssist and an MSI that sideloads HRUpdate.exe, a downloader that brute-forces ChaCha20 keys to decrypt embedded shellcode and retrieve the main module from hardcoded C2 URLs, and a main module that implements ChaCha20-encrypted Protobuf-over-HTTP(S) C2 with extensive capabilities (EXE/DLL/MSI/shellcode execution, process injection, system reconnaissance) and persistence via a scheduled task. The report describes runtime string decryption, dynamic API resolution, anti-analysis busy loops, per-host mutexing, and provides observed indicators and command IDs; ThreatLabz judges the actor likely intended to deploy ransomware with medium confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.