Researchers reported renewed activity involving Matanbuchus, a malware-as-a-service loader sold on Russian-speaking cybercrime forums, where it has been advertised for rent at roughly $2,500. In observed campaigns, attackers used phishing emails carrying ZIP attachments that led victims through a multistage infection chain: an HTML file dropped another ZIP archive containing an MSI installer, which wrote a DLL and VBS file to disk and invoked regsvr32.exe to execute the malicious DLL. The loader then performed anti-analysis checks, created persistence through a scheduled task, and contacted command-and-control infrastructure to retrieve its next-stage payload directly in memory.
Technical analyses showed that Matanbuchus uses obfuscated and encrypted strings, API hashing based on FNV1a, and HTTP communications to download follow-on malware while minimizing disk artifacts. Researchers linked the loader to deployments of Cobalt Strike Beacons and noted overlap with phishing operations involving other malware such as Qakbot. Reverse-engineering work also identified multiple infrastructure domains, sample hashes, and distinct loader and payload components, while updated YARA rules and configuration extractors improved detection of newer variants.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
DCSO CyTec published an analysis of a recent Matanbuchus sample, contributing additional public technical reporting on the malware family.
Cyble Research Labs analyzed a phishing campaign in which spam emails delivered a ZIP attachment leading to an MSI installer, in-memory Matanbuchus execution, and subsequent Cobalt Strike Beacon downloads.
OALABS released reverse-engineering notes on Matanbuchus covering its loader/downloader architecture, string decryption, infrastructure, and revised YARA detection logic.
SANS ISC analyzed a malicious spam campaign observed on 2022-06-16 in which ZIP-attached HTML lures led to an MSI installer that deployed Matanbuchus, established persistence, and fetched additional payloads. The observed infection chain culminated in downloads of Cobalt Strike-related files and HTTPS C2 traffic to extic[.]icu and reykh[.]icu.
0ffset Training Solutions published an analysis describing Matanbuchus as another loader-as-a-service, adding public technical coverage of the malware family.
Palo Alto Networks Unit 42 published a report on Matanbuchus as a malware-as-a-service offering, marking an early public documentation of the threat.
Researchers reported that the Matanbuchus malware loader was being offered for rent on Russian-speaking cybercrime forums starting in February 2021, with pricing beginning at $2,500.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourceblog.cyble.com
Open sourceresearch.openanalysis.net
Open sourceisc.sans.edu
Open source0ffset.net
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.