SYMBOLCOMMON_NAMEaka. SYNONYMS
win.matanbuchus (Back to overview)

Matanbuchus

VTCollection    

According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS). This piece of software is designed to cause chain infections.

Since it is used as a MaaS, both the malware it infiltrates into systems, and the attack reasons can vary - depending on the cyber criminals operating it. Matanbuchus has been observed being used in attacks against US universities and high schools, as well as a Belgian high-tech organization.

References
2026-02-16 ⋅ Huntress Labs ⋅ Anna Pham, Michael Tigges
ClickFix Won't Die. Neither Will Matanbuchus. A New RAT and a Hands-on-Keyboard Intrusion
AstarionRAT Matanbuchus
2025-12-09 ⋅ Recorded Future ⋅ Insikt Group
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries
CASTLELOADER Matanbuchus NightshadeC2 GrayBravo
2024-11-20 ⋅ Intrinsec ⋅ Equipe CTI
PROSPERO & Proton66: Tracing Uncovering the links between bulletproof networks
Coper SpyNote FAKEUPDATES GootLoader EugenLoader IcedID Matanbuchus Nokoyawa Ransomware Pikabot
2024-06-17 ⋅ Proofpoint ⋅ Proofpoint
From Clipboard to Compromise: A PowerShell Self-Pwn
DarkGate HijackLoader Lumma Stealer Matanbuchus NetSupportManager RAT TA571
2024-04-30 ⋅ Intrinsec ⋅ Intrinsec
Matanbuchus & Co: Code Emulation and Cybercrime Infrastructure Discovery
FAKEUPDATES Matanbuchus
2024-04-04 ⋅ Twitter (@embee_research) ⋅ Embee_research
TLS Certificate For Threat Intelligence - Identifying MatanBuchus Domains Through Hardcoded Certificate Values
Matanbuchus
2024-03-15 ⋅ cyber5w ⋅ M4lcode
Matanbuchus Loader Detailed Analysis
Matanbuchus
2022-12-05 ⋅ Cybereason ⋅ Kotaro Ogino, Ralph Villanueva, Robin Plumer
Threat Analysis: MSI - Masquerading as a Software Installer
Magniber Matanbuchus QakBot
2022-06-27 ⋅ CyberArk ⋅ Ben Cohen, The CyberArk Malware Research Team
Inside Matanbuchus: A Quirky Loader
Matanbuchus
2022-06-23 ⋅ cyble ⋅ Cyble Research Labs
Matanbuchus Loader Resurfaces
Cobalt Strike Matanbuchus
2022-06-19 ⋅ OALabs ⋅ Sergei Frankoff
Matanbuchus Triage Notes
Matanbuchus
2022-06-17 ⋅ SANS ISC ⋅ Brad Duncan
Malspam pushes Matanbuchus malware, leads to Cobalt Strike
Cobalt Strike Matanbuchus
2022-05-23 ⋅ DCSO ⋅ Colin Murphy, Johann Aydinbas
A deal with the devil: Analysis of a recent Matanbuchus sample
Matanbuchus
2022-05-22 ⋅ R136a1 ⋅ Dominik Reichel
Introduction of a PE file extractor for various situations
Cobalt Strike Matanbuchus
2022-02-15 ⋅ 0ffset Blog ⋅ Chuong Dong
MATANBUCHUS: Another Loader As A Service Malware
Matanbuchus
2021-06-16 ⋅ Palo Alto Networks Unit 42 ⋅ Jeff White, Kyle Wilhoit
Matanbuchus: Malware-as-a-Service with Demonic Intentions
Matanbuchus BelialDemon
Yara Rules
[TLP:WHITE] win_matanbuchus_auto (20260917 | Detects win.matanbuchus.)
rule win_matanbuchus_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.matanbuchus."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.matanbuchus"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b4508 8b483c 034d08 894dec }
            // n = 4, score = 500
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]
            //   8b483c               | mov                 ecx, dword ptr [eax + 0x3c]
            //   034d08               | add                 ecx, dword ptr [ebp + 8]
            //   894dec               | mov                 dword ptr [ebp - 0x14], ecx

        $sequence_1 = { e9???????? 8b45ec 0fb74814 83f960 7c09 }
            // n = 5, score = 500
            //   e9????????           |                     
            //   8b45ec               | mov                 eax, dword ptr [ebp - 0x14]
            //   0fb74814             | movzx               ecx, word ptr [eax + 0x14]
            //   83f960               | cmp                 ecx, 0x60
            //   7c09                 | jl                  0xb

        $sequence_2 = { 85d2 7502 ebb4 0fb745fc 83f803 7523 0fb74df8 }
            // n = 7, score = 500
            //   85d2                 | test                edx, edx
            //   7502                 | jne                 4
            //   ebb4                 | jmp                 0xffffffb6
            //   0fb745fc             | movzx               eax, word ptr [ebp - 4]
            //   83f803               | cmp                 eax, 3
            //   7523                 | jne                 0x25
            //   0fb74df8             | movzx               ecx, word ptr [ebp - 8]

        $sequence_3 = { 03481c 894dcc c745f000000000 eb09 8b55f0 }
            // n = 5, score = 500
            //   03481c               | add                 ecx, dword ptr [eax + 0x1c]
            //   894dcc               | mov                 dword ptr [ebp - 0x34], ecx
            //   c745f000000000       | mov                 dword ptr [ebp - 0x10], 0
            //   eb09                 | jmp                 0xb
            //   8b55f0               | mov                 edx, dword ptr [ebp - 0x10]

        $sequence_4 = { 33c0 e9???????? b808000000 6bc800 8b55ec 8b440a78 }
            // n = 6, score = 500
            //   33c0                 | xor                 eax, eax
            //   e9????????           |                     
            //   b808000000           | mov                 eax, 8
            //   6bc800               | imul                ecx, eax, 0
            //   8b55ec               | mov                 edx, dword ptr [ebp - 0x14]
            //   8b440a78             | mov                 eax, dword ptr [edx + ecx + 0x78]

        $sequence_5 = { 8b1481 035508 8955ec 0fb745fc 8b4dd8 668b1441 668955f8 }
            // n = 7, score = 500
            //   8b1481               | mov                 edx, dword ptr [ecx + eax*4]
            //   035508               | add                 edx, dword ptr [ebp + 8]
            //   8955ec               | mov                 dword ptr [ebp - 0x14], edx
            //   0fb745fc             | movzx               eax, word ptr [ebp - 4]
            //   8b4dd8               | mov                 ecx, dword ptr [ebp - 0x28]
            //   668b1441             | mov                 dx, word ptr [ecx + eax*2]
            //   668955f8             | mov                 word ptr [ebp - 8], dx

        $sequence_6 = { 8b4224 034508 8945d8 8b4df0 8b511c 035508 }
            // n = 6, score = 500
            //   8b4224               | mov                 eax, dword ptr [edx + 0x24]
            //   034508               | add                 eax, dword ptr [ebp + 8]
            //   8945d8               | mov                 dword ptr [ebp - 0x28], eax
            //   8b4df0               | mov                 ecx, dword ptr [ebp - 0x10]
            //   8b511c               | mov                 edx, dword ptr [ecx + 0x1c]
            //   035508               | add                 edx, dword ptr [ebp + 8]

        $sequence_7 = { 49 81c900f0ffff 41 66894df8 0fb755fc 85d2 }
            // n = 6, score = 500
            //   49                   | dec                 ecx
            //   81c900f0ffff         | or                  ecx, 0xfffff000
            //   41                   | inc                 ecx
            //   66894df8             | mov                 word ptr [ebp - 8], cx
            //   0fb755fc             | movzx               edx, word ptr [ebp - 4]
            //   85d2                 | test                edx, edx

        $sequence_8 = { 8b4508 8b483c 034d08 894dec 8b55ec 8b4234 8945e8 }
            // n = 7, score = 500
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]
            //   8b483c               | mov                 ecx, dword ptr [eax + 0x3c]
            //   034d08               | add                 ecx, dword ptr [ebp + 8]
            //   894dec               | mov                 dword ptr [ebp - 0x14], ecx
            //   8b55ec               | mov                 edx, dword ptr [ebp - 0x14]
            //   8b4234               | mov                 eax, dword ptr [edx + 0x34]
            //   8945e8               | mov                 dword ptr [ebp - 0x18], eax

        $sequence_9 = { 760b 8b45f0 8b4818 894de8 eb09 }
            // n = 5, score = 500
            //   760b                 | jbe                 0xd
            //   8b45f0               | mov                 eax, dword ptr [ebp - 0x10]
            //   8b4818               | mov                 ecx, dword ptr [eax + 0x18]
            //   894de8               | mov                 dword ptr [ebp - 0x18], ecx
            //   eb09                 | jmp                 0xb

    condition:
        7 of them and filesize < 13077504
}
Download all Yara Rules