#Matanbuchus
Threat actors are using unsolicited Microsoft Teams calls to trick corporate employees into infecting themselves with a new version (v3) of the Matanbuchus malware

www.morphisec.com/blog/ransomw...
Teams Call to Ransomware: Matanbuchus 3.0 MaaS Levels Up
Morphisec threat researchers share an in-depth analysis on Matanbuchus, a stealthy malware loader that has advanced its techniques in 2025.
www.morphisec.com
July 17, 2025 at 12:03 PM
The Matanbuchus malware loader has been seen being distributed through social engineering over Microsoft Teams calls impersonating IT helpdesk.
Microsoft Teams voice calls abused to push Matanbuchus malware
The Matanbuchus malware loader has been seen being distributed through social engineering over Microsoft Teams calls impersonating IT helpdesk.
www.bleepingcomputer.com
July 17, 2025 at 9:28 PM
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms
thehackernews.com
July 16, 2025 at 7:18 PM
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
December 9, 2025 at 11:25 AM
CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
www.recordedfuture.com
December 9, 2025 at 3:43 PM
7/ Another cluster, we track as TAG-161, impersonates Booking[.]com. This group also relies on ClickFix for CastleLoader delivery and deploys advanced payloads, including Matanbuchus.
December 9, 2025 at 8:24 AM
The Matanbuchus malware impersonates IT helpdesk personnel to gain interactive remote access: buff.ly/347dNdJ
#MicrosoftTeams #cybersecurity
How a new malware attack turns Microsoft Teams against you
The Matanbuchus malware loader has been distributed via social engineering on Microsoft Teams calls, impersonating IT helpdesk personnel to execute
buff.ly
July 22, 2025 at 10:44 AM
-LARVA-208 switches to Web3 devs
-New Maison Receipts service
-New protestware spreads on npm
-In-browser cryptojacking is still alive
-PQC support in SSH servers is only 6%
-Crypto-thefts this year reach $2.17b
-New Matanbuchus 3.0
-Russia runs extensive info-ops in the occupied territories
July 18, 2025 at 8:59 AM
🚨Alleged Sale of Matanbuchus 3.0 Malware Loader

darkwebinformer.com/alleged-sale...
Alleged Sale of Matanbuchus 3.0 Malware Loader
Alleged Sale of Matanbuchus 3.0 Malware Loader
darkwebinformer.com
July 7, 2025 at 5:23 PM
Matanbuchus Malware Resurfaces: Advanced Techniques Threaten Enterprises in 2025

In a worrying development for cybersecurity, the long-running Matanbuchus malware, first identified in 2020, has re-emerged with a new, more sophisticated version. Targeting businesses and organizations, Matanbuchus…
Matanbuchus Malware Resurfaces: Advanced Techniques Threaten Enterprises in 2025
In a worrying development for cybersecurity, the long-running Matanbuchus malware, first identified in 2020, has re-emerged with a new, more sophisticated version. Targeting businesses and organizations, Matanbuchus v3.0 demonstrates advanced evasion tactics, encrypted communication methods, and the ability to deliver secondary payloads that could lead to ransomware attacks. Recent analyses from Zscaler ThreatLabz reveal how this malware continues to evolve, leveraging modern obfuscation techniques and advanced persistence strategies that make detection and removal increasingly challenging.
undercodenews.com
December 3, 2025 at 12:08 PM
Wo soll ich anfangen 🥺 Lasst mich das so formulieren: Wer auf links klickt handelt grob fahrlässig!

Malvertising ist nicht neu. Awareness könnte ein bisschen helfen. Dazu müsste aber Medienkompetenz schon in der Kindergrippe vermittelt werden!

thehackernews.com/2025/07/hack...
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms
Matanbuchus 3.0 malware loader evolves with advanced stealth techniques, targeting companies via social engineering tactics.
thehackernews.com
July 27, 2025 at 7:28 PM
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms

#thehackersnews
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms
Matanbuchus 3.0 malware loader evolves with advanced stealth techniques, targeting companies via social engineering tactics.
thehackernews.com
July 16, 2025 at 6:00 PM
Feed: "Cyber Security News"
By: Varshini on Wednesday, February 18, 2026
ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack
Cybersecurity researchers uncovered a sophisticated attack chain where attackers used ClickFix social engineering to deliver Matanbuchus 3.0
cyberpress.org
February 18, 2026 at 6:13 PM
🚨Alleged sale of Matanbuchus 2.0 source code for 15K
July 2, 2025 at 8:28 PM
Morphisec threat researchers share an in-depth analysis on Matanbuchus, a stealthy malware loader that has advanced its techniques in 2025.
Teams Call to Ransomware: Matanbuchus 3.0 MaaS Levels Up
www.morphisec.com
July 18, 2025 at 2:33 PM
Matanbuchus is the name given to a malware-as-a-service (MaaS) offering that can act as a conduit for next-stage payloads, including Cobalt Strike beacons and ransomware.

www.tsfactory.com/forums/blog/...

#microsoftteams #hackers #cybersecurity
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms - Community
Cybersecurity researchers have flagged a new variant of a known malware loader called Matanbuchus that packs in significant features to enhance its stealth and evade detection. Matanbuchus is the name...
www.tsfactory.com
July 17, 2025 at 11:20 AM
“Microsoft Teams phishing spreads updated Matanbuchus malware loader” — SC Media

#PhishingNews #Phishing #Malware
July 17, 2025 at 1:11 AM
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms

Cybersecurity researchers have flagged a new variant of a known malware loader called Matanbuchus that packs in significant features to enhance its stealth and evade detection.
Matanb…

#hackernews #microsoft #news
Hackers Leverage Microsoft Teams to Spread Matanbuchus 3.0 Malware to Targeted Firms
Cybersecurity researchers have flagged a new variant of a known malware loader called Matanbuchus that packs in significant features to enhance its stealth and evade detection. Matanbuchus is the name given to a malware-as-a-service (MaaS) offering that can act as a conduit for next-stage payloads, including Cobalt Strike beacons and ransomware. First advertised in February 2021 on
thehackernews.com
July 17, 2025 at 5:34 PM
September 11, 2025 at 7:14 PM
🚨 A threat actor has released Matanbuchus 3.0 and now selling Matanbuchus 2.0 on a darknet forum for $15K. The offer includes full source code, DLL hijacking tools, payload builder project, setup instructions, and OpSec guidance.
#ThreatIntel #Malware #DarkWeb #Infosec
July 14, 2025 at 5:52 AM
Hey y'all, this month's Intelligence Insights is out! We had two new birds make the list:
- Infrared Ibis == how we track behavior related to malicious chrome extensions
- Saffron Starling == our name for a loader that delivers Danabot/DarkGate/Matanbuchus

redcanary.com/blog/threat-...
Intelligence Insights: February 2025
Infrared Ibis infiltrates Chrome extensions and Saffron Starling surprises in this month's edition of Intelligence Insights
redcanary.com
February 20, 2025 at 9:37 PM
Microsoft Teamsの音声通話がMatanbuchusマルウェアの拡散に悪用される
#CybersecurityNews
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com
July 18, 2025 at 6:54 AM