MATA is a modular, multiplatform backdoor framework with Windows, Linux and macOS implementations. Its earliest identified artifacts date to approximately April 2018. The framework comprises loaders, orchestrators and dynamically loaded plugins that provide extensive remote control over compromised systems. MATA has been linked to the North Korean Lazarus Group through shared artifacts and configuration similarities with Manuscrypt.
MATA supports command execution, process creation and termination, file searching and transfer, file wiping, system and network reconnaissance, and code injection. Its networking components provide connectivity testing, public-address scanning, reverse proxying and chained communications through compromised hosts. Plugins can execute in memory, and variants employ encrypted configurations and communications, multiple transport protocols and active or passive command-and-control modes. Windows generations include service-based execution and persistence. A USB-based component exchanges encrypted commands and collected data through removable media, enabling operation across air-gapped network boundaries.
MATA has targeted corporate environments worldwide, including software development, e-commerce and internet service providers. A campaign active from mid-August 2022 through May 2023 targeted more than a dozen Eastern European corporations, particularly defense and oil-and-gas organizations. Delivery included spear-phishing documents linking to an exploit for CVE-2021-26411 and malicious browser downloads. Attackers compromised domain controllers and abused centralized security-management systems to deploy Windows and Linux payloads across subsidiaries. This activity introduced updated generations, including the rewritten Windows backdoor MataDoor and generation 5, alongside separate information stealers and endpoint-security bypass tools.
A macOS implementation was delivered through a trojanized two-factor authentication application. MATA has also been used to search corporate databases for customer information and distribute VHD ransomware; successful customer-database exfiltration was not confirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In some cases, we observed the actor took advantage of a public exploit called CallbackHell to escalate privilege and bypass endpoint security products. The exploit, which we discovered and reported in 2021, triggers CVE-2021-40449 vulnerability, a use-after-free vulnerability, in Win32k’s NtGdiResetDC API.
Each phishing document contains an external link to fetch a remote page containing a CVE-2021-26411 exploit.
It included a Windows MATA orchestrator, a Linux tool for listing folders, scripts for exploiting Atlassian Confluence Server (CVE-2019-3396), a legitimate socat tool and a Linux version of the MATA orchestrator bundled together with a set of plugins. | The MATA malware framework possesses several components, such as loader, orchestrator and plugins. This comprehensive framework is able to target Windows, Linux and macOS operating systems.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The MATA malware framework possesses several components, such as loader, orchestrator and plugins. This comprehensive framework is able to target Windows, Linux and macOS operating systems.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
In this instance, we believe initial access was achieved through opportunistic exploitation of a vulnerable VPN gateway.
Additionally, we found another victim within the same corporation compromised by the MATA malware, although executed via Windows task scheduler.
118 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive malware framework described as the delivery mechanism for VHD ransomware and attributed in the article to North Korean operators.
Modular malware used in a campaign targeting more than a dozen Eastern European oil and gas and defense companies from August 2022 through May 2023. Newly observed generations provide extensive remote control, multiple command-and-control protocols, and flexible proxy chains. Attackers distributed Windows and Linux variants, including through compromised security-management systems. A USB module transports commands and collected data across air-gapped networks. The campaign also employed loaders, credential and cookie stealers, screenshot capture, and endpoint-security bypass techniques.
A multi-stage, modular backdoor platform attributed in prior reporting to Lazarus, used for targeted intrusions. It supports multiple C2 protocols (e.g., TCP/UDP/SSL/DTLS variants), complex proxy chaining inside victim networks, plugin/module-based command execution (file/process/net recon/proxy/inject/monitoring), and includes Windows and Linux variants. Later generations (gen4/gen5) show major rewrites, richer protocol stacks, IPC-based internal architecture (gen5), and capabilities to operate in constrained/segmented environments (including proxy chains and air-gapped support via related USB module).
Modular Lazarus-linked malware framework/backdoor with multi-stage delivery; includes variants for Linux and capabilities for proxy chaining and complex C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.