Threats Tagged 'matanbuchus'
View all threats tagged with 'matanbuchus'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'matanbuchus'
Click on any threat for detailed analysis and mitigation recommendations
Insikt Group has identified four distinct activity clusters associated with GrayBravo's CastleLoader malware, each with unique tactics and victim profiles. This supports the assessment that GrayBravo operates a malware-as-a-service model. One cluster, TAG-160, impersonates logistics firms and uses phishing lures with the ClickFix technique to distribute CastleLoader. Another cluster, TAG-161, impersonates Booking.com and employs similar techniques. The analysis also uncovered potential links to the online persona "Sparja" and the broader cybercriminal ecosystem. GrayBravo demonstrates rapid evolution, technical sophistication, and adaptability in response to public exposure. The report recommends various security measures to defend against these threats. Join the discussion | AlienVault OTX General | 12/09/2025, 05:39:34 UTC Added: 12/09/2025, 12:43:02 UTC |
Matanbuchus 3.0 is a sophisticated C++ malware downloader offered as Malware-as-a-Service since 2020, designed to deliver additional malicious payloads including ransomware and remote access trojans like Rhadamanthys and NetSupport RAT. It employs advanced obfuscation techniques such as junk code insertion, encrypted strings, and API hashing to evade detection. The malware features anti-analysis mechanisms including an expiration date and persistence via scheduled tasks. It communicates with its command and control servers using encrypted Protocol Buffers over HTTP(S), supporting a wide range of commands for payload execution, data collection, and system manipulation. While no known exploits are currently reported in the wild, its modular design and use in ransomware campaigns make it a medium-severity threat. European organizations are at risk due to the malware’s capability to facilitate ransomware attacks and backdoor access, potentially leading to data breaches and operational disruption. Mitigation requires targeted detection of its persistence mechanisms, network traffic analysis for encrypted C2 communications, and blocking associated domains and URLs. Countries with high technology adoption and ransomware targeting history, such as Germany, France, the UK, Italy, and the Netherlands, are most likely to be affected. Join the discussion | AlienVault OTX General | 12/03/2025, 08:47:17 UTC Added: 12/03/2025, 11:01:25 UTC |
ChillyHell is a sophisticated macOS backdoor discovered in 2021 that has evaded detection by antivirus vendors. It is a modular C++ malware targeting Intel architectures, using multiple persistence mechanisms and communication protocols. The backdoor performs host profiling, establishes persistence through LaunchAgents, LaunchDaemons, or shell profile injection, and communicates with command and control servers via DNS or HTTP. ChillyHell's modular structure allows for various capabilities, including reverse shell access, self-updating, payload execution, and local password cracking. The malware's flexibility, stealth techniques, and notarization status make it a significant threat in the macOS landscape. Join the discussion | AlienVault OTX General | 09/10/2025, 16:18:10 UTC Added: 09/10/2025, 19:45:51 UTC |
Matanbuchus 3.0, a malware loader available as Malware-as-a-Service, has evolved with significant updates. It now employs sophisticated techniques including improved communication protocols, in-memory stealth capabilities, enhanced obfuscation, and support for WQL queries, CMD, and PowerShell reverse shells. The loader collects detailed system data, including information on EDR security controls, to tailor subsequent attacks. It can execute various commands through regsvr32, rundll32, msiexec, or process hollowing. The malware establishes persistence through scheduled tasks and registry modifications. Recent campaigns have targeted victims through external Microsoft Teams calls impersonating IT helpdesks, leading to potential ransomware compromises. Join the discussion | AlienVault OTX General | 07/18/2025, 09:01:17 UTC Added: 07/18/2025, 09:03:17 UTC |
Showing 1 to 4 of 4 results