Matanbuchus is a malware-as-a-service that first surfaced back in 2021 but has since resurfaced; threat researchers recently discovered a malicious phishing campaign that spreads the malware in order to drop Cobalt Strike beacons on compromised machines. Cobalt Strike is a penetration testing product that is also widely used by threat actors.
Like other malware loaders, Matanbuchus is engineered to download and execute other executables on the target system, evading detection and opening the way to wider exploitation. Matanbuchus’ capabilities are extensive and include the ability to launch a .exe or .dll directly to memory, add or modify task schedules, launch customer PowerShell commands, and leverage a standalone executable to load malicious DLLs.
It’s an extremely dangers malware and can drop tons of threats on compromised systems. Explore the Matanbuchus Spotlight and learn more about this menacing malware.