A new and significantly upgraded version of Matanbuchus, one of the most widespread malware loaders in the Malware–as–a–Service (MaaS), has been detected by cybersecurity experts. Matanbuchus 3.0 brings with it a combination of stealth, advanced obfuscation techniques, and increased attack capabilities, confirming that cybercrime platforms are maturing to dangerous levels.

Since its first appearance on Russian-language hacking forums in 2021, Matanbuchus has been operating as a malware loader that installs additional malicious payloads on compromised systems. These may include:
- Cobalt Strike beacons (useful for lateral movement),
- Ransomware strains, but also
- Banking trojans like DanaBot or QakBot.
The new Matanbuchus 3.0 takes stealth functionality to the next level. According to researchers at Morphisec, this variant was spotted in a recent cyberattack incidentwhere attackers targeted a company, posed as IT support via Microsoft Teams , and managed to trick employees into activating Quick Assist (for remote access). This was followed by the execution of a malicious PowerShell scriptthat delivered the loader to the target.
See also: HazyBeacon malware steals government data via AWS Lambda
“ Victims are carefully targeted and convinced to execute a script that triggers the download of a file ,” said Morphisec CTO Michael Gorelik. “ This file contains a renamed Notepad++ updater (GUP), a slightly modified XML configuration file, and a malicious side-loaded DLL that represents the Matanbuchus loader .”
The new features of Matanbuchus 3.0
The third version of the software incorporates a multitude of techniques aimed at bypassing detection by antivirus and EDR systems:
- Enhanced communication channels (HTTPS & DNS C2)
- CMD and PowerShell reverse shell support
- Execution of DLL, EXE and shellcode payloads
- Hiding through in-memory techniques and COM hijacking
- Collect information about active processes and applications
Increasing flexibility and new attack tactics
Matanbuchus 3.0 is mainly delivered via spear-phishing and fake MSI installations, and has also been observed using malvertising .What is special, however, is the way it exploits legitimate tools, such as:
- Microsoft Teams & Zoom, through social engineering techniques
- LOLBins (Living off the Land Binaries), such as regsvr32, rundll32, msiexec
- WQL queries and API string resolution to avoid detection
The pricing now reaches $10,000 per month for HTTPS and $15,000 for the DNS-based variant, an element that indicates professionalism and strategic commercialization of the software.
See also: Android malware Konfety uses new obfuscation tactics
A threat with broader implications in cyberspace
Matanbuchus 3.0 does not act in isolation. Instead, it is part of an ecosystem of stealth-first loaders, along with tools like IceID, Bumblebee, and Raspberry Robin, that act as digital bridges for ransomware attacks and Advanced Persistent Threats (APTs).
Recent Matanbuchus tactics have been observed in campaigns associated with the Black Basta group, showing the potential interconnection of MaaS infrastructures with ransomware groups. As attacks become increasingly targeted, corporate tools and technical support are becoming “Trojan Horses” for social engineering attacks.

What organizations should do – Recommendations for resilience
1. Train employees on social engineering techniques.
Using platforms like Microsoft Teams to deceive staff requires ongoing awareness and technical guidance.
2. Adopt Zero Trust and minimize privileges
Loaders check if they are running with admin privileges. Limiting these to critical applications can prevent escalation.
3. Monitoring in-memory and LOLBins activity
Classic AV mechanisms often fail to detect shellcode injection and COM hijacking.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
4. Detecting anomalies in application behavior
The use of tools such as msiexec or rundll32 for unexpected processes can be a trigger for incident investigation.
5. Collaborate with Managed Detection & Response (MDR) providers.
Sophisticated malware loaders, like Matanbuchus, require continuous event analysis and live response.
See also: Interlock ransomware group uses new RAT malware
Matanbuchus 3.0 demonstrates that Malware-as-a-Service is rapidly evolving, adopting stealth-by-default models. Cyberspace is no longer just home to traditional malware, but to structured, agile attack platforms. Organizations are being challenged to adopt a multi-layered approach to security — not just with technological measures, but also with a strategic understanding of the threat,
Source: thehackernews.com
