Matanbuchus is a commercial C++ malware loader for Windows, developed by BelialDemon and advertised as malware-as-a-service on Russian-speaking cybercrime forums since February 2021. It uses a multistage architecture to retrieve and execute additional malware. Observed payloads include Qakbot, Cobalt Strike, Rhadamanthys, NetSupport RAT, and AstarionRAT. Documented targeting includes technology companies and educational institutions.
Delivery campaigns use phishing and malicious spam, including scanned-document lures and HTML smuggling that produces archives containing malicious Windows Installer packages. Installers have impersonated Adobe font packages and Visual Studio software, sometimes displaying fake installation errors while executing the loader. Other campaigns use ClickFix or Microsoft Teams voice-based IT-support impersonation and abuse of Quick Assist to persuade victims to install malicious packages.
Matanbuchus supports execution of executables, DLLs, shellcode, PowerShell, and command-shell tasking. Its loader can manually map components and payloads into its own process without writing them to disk. It collects host and security-product information, reports to command-and-control infrastructure, supports self-updating, and establishes persistence through scheduled tasks. Evasion mechanisms include string encryption, hashed API resolution, debugger and sandbox checks, environment-dependent execution gating, and abuse of trusted Windows execution utilities. Earlier variants exchange encoded JSON with RC4-encrypted values.
Matanbuchus 3.0, introduced in July 2025 as a substantial rewrite, uses Protobuf-serialized command-and-control over HTTPS with ChaCha20 encryption. It enumerates more than 70 endpoint-security products and uses Heaven’s Gate transitions to bypass WoW64 user-mode hooks. Observed execution chains use two DLL-sideloading stages involving legitimate signed applications, with an embedded Lua interpreter and a reflective PE loader supporting final-payload execution. Its principal role is payload delivery and execution; credential theft, account takeover, and lateral movement in associated intrusions may be performed by downstream malware or operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This dll file belongs to the Matanbuchus malware family, and it is trying to download additional payloads through C&C servers.
If the “Auto-fix” button was clicked, the search-ms protocol displayed a similar WebDAV-hosted “fix.msi” or “fix.vbs” in Windows Explorer... This led to the installation of Matanbuchus.
According to threat intelligence shared by Google Mandiant, UNC4487 is a suspected espionage actor that has been observed compromising the websites of Ukrainian government entities to redirect and socially engineer targets to execute Matanbuchus or CHILLYHELL malware.
The campaign, internally dubbed "FortiSync Quasar," revealed an evolution from ransomware operations to strategic espionage, deploying Matanbuchus 3.0, Astarion RAT, and SystemBC.
“uses ClickFix techniques to deliver CastleLoader and Matanbuchus”
34 distinct techniques documented for this family, organized by ATT&CK tactic.
malicious Google ads directed users to an attacker-controlled page... Users are then directed to download a ZIP file
The Matanbuchus infection starts through spam emails containing a ZIP attachment.
To establish persistence, the malware creates a scheduled task to run the 8c01.nls file with a specific function by using the following command line.
Creates scheduled task Update Tracker Task via %WINDIR%\SysWOW64\msiexec.exe -z %Matanbuchus_path%.
Avoid extracting malicious ZIP archives, and executing LNK files, or script files without conducting thorough analysis
The Threat actor embedded the malicious zip file in the JavaScript in base64 format.
Next, the malware manually resolves the addresses of imported APIs in the PE’s import table... calls GetProcAddress to retrieve its address from the loaded library
To establish persistence, the malware creates a scheduled task to run the 8c01.nls file with a specific function by using the following command line.
crypters, which are also referred to as loaders or packers, are applications designed to encrypt and obfuscate malware to evade detection by antivirus (AV) scanners and hinder analysis.
Installed under fake vendor names and used C:\ProgramData\USOShared\, which mimics a Windows Update staging directory.
Matanbuchus brute-forces ChaCha20 decryption of the INFO file and decrypts the downloaded main module in 8KB ChaCha20 chunks.
launching it through Regsvr32.exe ... this task will execute the regsvr32.exe command to register the downloaded DLL
The Matanbuchus payload connects to C&C server hxxp://collectiontelemetrysystem[.]com/cAUtfkUDaptk/ZRSeiy/requets/index.php and sends the base64-encoded POST request.
Finally, Matanbuchus malware downloads two Cobalt Strike Beacons from the C&C servers.
318 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A premium C++ malware loader sold as MaaS that performs adaptive payload delivery by enumerating installed EDR products, reporting them to C2, and allowing operators to choose execution methods accordingly. It supports multiple payload formats, uses Protobuf-over-HTTPS with ChaCha20 encryption, employs Heaven's Gate and DLL sideloading for evasion, and has delivered RATs, stealers, Cobalt Strike, and unspecified ransomware.
A premium malware-as-a-service loader that performs EDR discovery, reports the installed security stack to its operator, and supports adaptive payload delivery and execution. Version 3.0 uses encrypted Protobuf-over-HTTPS C2, DLL sideloading, Heaven's Gate to evade WoW64 userland hooks, scheduled-task persistence, and reflective payload loading.
A malware-as-a-service loader referenced as used in a prior ClickFix case.
Loader used in a related ClickFix campaign to deliver MIMICRAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.