Hackers Use Microsoft Teams to Distribute Matanbuchus 3.0 Malware to Targeted Companies

Published:

spot_img

Understanding Matanbuchus 3.0: A Rising Threat in Cybersecurity

Cybersecurity researchers have recently issued warnings about a new variant of malware known as Matanbuchus 3.0, which showcases advanced capabilities designed to enhance its stealth and avoid detection.

What is Matanbuchus?

Matanbuchus refers to a malware-as-a-service (MaaS) model that serves as a platform to deliver various types of malicious payloads, including notorious threats like Cobalt Strike beacons and ransomware. This malware first emerged in February 2021, being advertised on Russian-speaking cybercrime forums for a rental fee of $2,500. Its deceptive tactics often involve using ClickFix-like lures to trick users into engaging with compromised sites that do not host the malware directly.

Distribution Methods

Unlike many traditional malware variants that rely heavily on spam emails or drive-by downloads, Matanbuchus is typically disseminated via social engineering. Attackers leverage direct interactions to deceive their victims. This method of operation makes Matanbuchus more targeted and coordinated compared to standard commodity loaders. It has been utilized as an entry point for brokers who provide initial access to ransomware groups, exposing a more sophisticated approach to cybercriminal activities.

New Features in Matanbuchus 3.0

The latest iteration, Matanbuchus 3.0, integrates several innovative features that significantly enhance its capabilities. These improvements include:

  • Enhanced Communication Protocols: New techniques for secure communication with command-and-control (C2) servers.
  • In-memory Execution: The ability to run code within memory, reducing the risk of detection.
  • Advanced Obfuscation Methods: Techniques that disguise malicious code to evade traditional security measures.
  • CMD and PowerShell Reverse Shell Support: Enabling attackers to execute remote commands stealthily.
  • Multi-format Payload Capability: Matanbuchus 3.0 can execute next-stage payloads, including DLLs and EXEs.

Recently, Morphisec, a cybersecurity firm, detailed how this malware was deployed in a real-world incident targeting an unnamed organization. Attackers conducted external Microsoft Teams calls impersonating IT support, leading employees to launch remote assistance tools that enabled execution of a PowerShell script which instigated the Matanbuchus payload.

Tactics Employed by Cybercriminals

The tactics used to distribute Matanbuchus mirror those utilized by well-known threat actors, such as those from the Black Basta ransomware operation. According to Morphisec’s Chief Technology Officer, Michael Gorelik, victims are often meticulously targeted. A carefully constructed script is executed, initiating a download that features an archive camouflaged as a Notepad++ updater, alongside a modified configuration file, all designed to facilitate the Matanbuchus loader.

For those interested in accessing this malware, it has been publicly listed for a monthly fee of $10,000 for its HTTPS version and $15,000 for its DNS version.

Functionality and Behavioral Patterns

Once activated, Matanbuchus 3.0 begins by gathering extensive system information. It assesses all running processes to identify security tools present and determines if it has administrative privileges. This information is relayed to a C2 server, effectively opening the door for additional malicious payloads, such as MSI installers.

Persistence is a key component of its operation. Matanbuchus establishes a scheduled task to maintain its foothold on compromised systems. Gorelik elaborates on the sophistication involved in these processes, indicating that invoking a task timetable utilizes COM and clever shellcode techniques. This provides a level of stealth and effectiveness that enhances the malware’s threat profile.

Increasing Complexity of Executions

The loader’s functionalities extend beyond initial deployment. It can remotely collect data on executing processes, active services, and installed applications—capabilities that make it significantly dangerous. Gorelik mentions, “Matanbuchus 3.0 has transformed into a sophisticated threat,” with its upgraded features setting it apart from earlier versions.

The loader’s flexibility is notable; it can execute various commands, such as regsvr32, rundll32, and msiexec, underlining its adaptability and growing complexity. The emergence of Matanbuchus highlights a broader trend toward the development of stealth-oriented malware loaders, which exploit living-off-the-land binaries (LOLBins) and other methodologies to evade detection.

The Importance of Threat Landscape Awareness

As cyber threats evolve, understanding the complexities tied to malware like Matanbuchus 3.0 becomes critical. Cybersecurity professionals are increasingly integrating mappings of these sophisticated loaders into their attack surface management strategies. A significant aspect of this strategy focuses on the misuse of enterprise collaboration tools such as Microsoft Teams and Zoom, which are now common vectors for attacks.

By recognizing these patterns and the tools employed by malicious actors, organizations can better fortify their defenses against emerging threats.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...