BelialDemon is a financially motivated malware developer and underground-market seller associated with Matanbuchus and TriumphLoader. Matanbuchus is a C++ malware loader marketed as Malware-as-a-Service on Russian-speaking cybercrime forums since February 2021. Its commercial distribution does not establish the developer's nationality or operating location. Matanbuchus downloads and executes additional payloads, supports arbitrary PowerShell execution, and establishes persistence. Delivery campaigns have used phishing attachments, HTML smuggling, and malicious Windows Installer packages masquerading as legitimate software. These installers can display false installation errors while executing malware through trusted Windows utilities. Later campaigns have used ClickFix social engineering and Microsoft Teams helpdesk impersonation with Quick Assist abuse. Matanbuchus 3.0, advertised in July 2025 as a rewritten platform, supports multiple executable and script formats, encrypted command-and-control, security-product discovery, scheduled-task persistence, and layered DLL sideloading. Its defense-evasion techniques include anti-debugging and sandbox checks, encrypted strings and shellcode, API hashing, and Heaven's Gate transitions intended to bypass WoW64 user-mode hooks. Matanbuchus has delivered Cobalt Strike, QakBot, DanaBot, Rhadamanthys, NetSupport RAT, and AstarionRAT. Downstream operators using the platform have conducted lateral movement, created unauthorized domain accounts, and modified Microsoft Defender exclusions. Such customer activity does not establish that BelialDemon personally conducted those intrusions. No specific victim geography or industry focus is established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
47 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer and seller of the Matanbuchus malware-as-a-service loader, which is used by customers to deliver RATs, infostealers, Cobalt Strike, and potentially ransomware payloads.
Advertised and sold the Matanbuchus MaaS loader on Russian-speaking cybercrime forums (initially in 2021), positioning it as a premium loader used for high-value, targeted intrusions that can deliver follow-on payloads (e.g., Cobalt Strike, QakBot, DanaBot, Rhadamanthys, NetSupport RAT).
Developed and operated the MatanBuchus MaaS/loader platform, which is delivered via phishing chains and MSI installers that drop and execute payload components, enabling payload download/execution and C2 communications.
CYFIRMA attributes the reported Matanbuchus loader campaign to BelialDemon. The campaign delivers malicious HTML email attachments that reconstruct a ZIP archive containing an MSI installer. The installer masquerades as an Adobe Font Pack, displays a fake error, and deploys the Matanbuchus DLL. The loader attempts to retrieve Cobalt Strike Beacon from command-and-control servers, which were inactive at the time of analysis. The report describes Matanbuchus as malware-as-a-service offered for $2,500 since February 2021.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.