HomeSecurityMatanbuchus malware compromises Windows machines

Matanbuchus malware compromises Windows machines

Matanbuchus malware has been reported to be launching a new campaign, exploiting XLS files to compromise Windows machines.

See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

Matanbuchus malware Windows

This sophisticated threat, known for its loader-as-a-service, has been active for several years and poses a risk to users around the world. Matanbuchus malware, a name that has become increasingly well-known among cybersecurity experts, has found a new method of infiltrating systems .

By exploiting malicious XLS files, the malware retrieves a JavaScript (JS) file, which then downloads a malicious Dynamic Link Library (DLL), signaling the beginning of a potential “cascade” of infections. This technique highlights the evolving nature of cyber threats and the constant need for vigilance.

The Matanbuchus malware, which first appeared in 2021, has not only persisted but has evolved, demonstrating the adaptability and persistence of cybercriminals, primarily targeting Windows systems. As a loader, its primary function is to facilitate the download and execution of other malicious payloads, essentially acting as a gateway for further exploitation.

Its capabilities are highly sophisticated, allowing for direct execution of .exe or .dll, task scheduler modifications, custom PowerShell , and standalone executables to load additional malicious DLLs. One of the most concerning aspects of Matanbuchus is its association with Cobalt Strike.

See also: “TicTacToe Droppers” are used to distribute malware

Matanbuchus malware compromises Windows machines

While a legitimate penetration testing tool, Cobalt Strike has been co-opted by threat actors for malicious purposes. The malware's ability to infiltrate compromised machines significantly enhances the threat actors' control over the infected system, allowing for a wide range of malicious activities.

Broadcom revealed the Matanbuchus malware campaign, which involves the use of a malicious XLS file to attack Windows machines. This campaign is designed to exploit vulnerabilities in Microsoft Excel and allow threat actors to execute malicious code on target systems.

Specific identifiers such as ACM.Ps-Rd32!g1, Scr.Malcode!gen, Trojan.Gen.MBT, and Trojan.Mdropper, among others, have been developed to identify and neutralize threats posed by Matanbuchus.

See also: Mobile malware: A major risk for businesses

What are the main functions of Loader-as-a-Service?

A Loader-as-a-Service, such as the Matanbuchus malware affecting Windows systems, is a service that facilitates the process of loading data into a database or storage system. Its first key function is to automate the data loading process, eliminating the need for manual data entry. In addition, Loader-as-a-Service provides mechanisms for extracting ,cleaning, and transforming data before loading. This allows businesses to process and prepare data for analysis and reporting with greater efficiency. Finally, Loader-as-a-Service allows for easy integration of data from multiple sources.

Source: gbhackers

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS