惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Securelist
AI
AI
S
Schneier on Security
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
C
Cybersecurity and Infrastructure Security Agency CISA
T
Threat Research - Cisco Blogs
T
Tenable Blog
G
GRAHAM CLULEY
腾讯CDC
L
Lohrmann on Cybersecurity
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
The Cloudflare Blog
P
Proofpoint News Feed
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
AWS News Blog
AWS News Blog
D
Docker
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Latest news
Latest news
L
LINUX DO - 热门话题
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
L
LangChain Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
W
WeLiveSecurity
Blog — PlanetScale
Blog — PlanetScale
云风的 BLOG
云风的 BLOG
P
Privacy International News Feed
Cloudbric
Cloudbric
Attack and Defense Labs
Attack and Defense Labs
量子位
爱范儿
爱范儿
F
Fortinet All Blogs
博客园 - 三生石上(FineUI控件)
V
Vulnerabilities – Threatpost
Schneier on Security
Schneier on Security
J
Java Code Geeks
S
Security @ Cisco Blogs
N
News and Events Feed by Topic
N
Netflix TechBlog - Medium
博客园 - 司徒正美
I
InfoQ
WordPress大学
WordPress大学
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News

Security Research | Blog

Targeted Attack on Middle East Govts (Part 1) | ThreatLabz ClaudeFix: Shared Claude Chats Meet ClickFix | Zscaler Why Do F1 Teams Need Cybersecurity, and What Is AI’s Role? Indirect Prompt Injection Targets AI Agents | ThreatLabz Splunk Enterprise RCE (CVE-2026-20253) | ThreatLabz Edgecution: Malicious Edge Extension Backdoor | ThreatLabz SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler Shai-Hulud: Miasma, Hades, & AI Scanner Evasion | ThreatLabz Zscaler ThreatLabz 2026 Phishing and Initial Access Report Technical Analysis of MLTBackdoor | ThreatLabz When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing | Zscaler OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz Tropic Trooper: AdaptixC2 + Custom Beacon | ThreatLabz Do not delete blog (testing) | Zscaler Payouts King Takes Aim at the Ransomware Throne | ThreatLabz The Alibaba Incident and Why Zero Trust Matters More Than Ever In-Memory Loader Drops ScreenConnect | ThreatLabz Supply Chain Attacks Surge in March 2026 | ThreatLabz Claude Code Leak: Critical AI Security Threat 2026 Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz CVE-2026-20131: Analysis of FMC RCE | ThreatLabz Technical Analysis of SnappyClient | ThreatLabz China-nexus Group Targets Arabian Gulf Region | ThreatLabz Middle East Conflict Fuels Cyber Attacks | ThreatLabz Dust Specter APT Targets Gov’t Officials in Iraq | ThreatLabz APT37 Adds New Tools For Air-Gapped Networks | ThreatLabz GuLoader Malware Obfuscation Techniques Analyzed GuLoader Obfuscation Analysis | ThreatLabz Technical Analysis of Marco Stealer | ThreatLabz Latest Public Sector AI Adoption Trends: What Government, Healthcare, and Education Security Teams Need to Know | Zscaler Operation Neusploit: APT28 Uses CVE-2026-21509 | ThreatLabz 7 Predictions for 2026 | Zscaler SHEETCREEP, FIREPOWER, and MAILCREEP Analysis | ThreatLabz AI is Now Default Enterprise Accelerator: Takeaways from ThreatLabz 2026 AI Security Report | Zscaler GOGITTER, GITSHELLPAD, and GOSHELL Analysis | ThreatLabz Malicious NPM Packages Deliver NodeCordRAT | ThreatLabz What’s Powering Enterprise AI in 2025: ThreatLabz Report Sneak Peek | Zscaler BlindEagle Deploys Caminho and DCRAT | ThreatLabz Technical Analysis of the BlackForce Phishing Kit | ThreatLabz React2Shell RCE Vulnerability (CVE-2025-55182) | ThreatLabz Shai-Hulud V2 Poses Risk to NPM Supply Chain | ThreatLabz In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered CVE-2025-50165: Windows Graphics Component Flaw | ThreatLabz Mobile, IoT, and OT Risks Converge in the Public Sector | Zscaler Industry Attacks Surge, Mobile Malware Spreads: The ThreatLabz 2025 Mobile, IoT & OT Report | Zscaler Zscaler Discovers Vulnerability in Keras Models Allowing Arbitrary File Access and SSRF (CVE-2025-12058) | Zscaler F5 Security Incident Advisory | Zscaler Under the Radar: How Non-Web Protocols Are Redefining the Attack Surface | Zscaler SEO Poisoning Targets Ivanti VPN: Credential Theft Alert Cisco Firewall and VPN Zero Day Attacks | ThreatLabz COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz YiBackdoor: Linked to IcedID and Latrodectus | ThreatLabz Technical Analysis of Zloader Updates | ThreatLabz Mitigating Risks from the Shai-Hulud NPM Worm | ThreatLabz Malicious PyPI Packages Deliver SilentSync RAT | ThreatLabz Technical Analysis of SmokeLoader Version 2025 | ThreatLabz Technical Analysis of kkRAT | ThreatLabz APT37: Rust Backdoor & Python Loader | ThreatLabz Anatsa’s Latest Updates | ThreatLabz Termncolor and Colorinal Explained | ThreatLabz GenAI Used to Impersonate Brazil’s Govt Websites | ThreatLabz Tracking Updates to Raspberry Robin | ThreatLabz Ransomware Surges, Extortion Escalates: ThreatLabz 2025 Ransomware Report | Zscaler China-nexus APT Targets the Tibetan Community | ThreatLabz CVE-2025-53770 | ThreatLabz Black Hat SEO Poisoning Search Engine Results For AI | ThreatLabz
Technical Analysis of Matanbuchus 3.0 | ThreatLabz
ThreatLabz · 2025-12-02 · via Security Research | Blog

Matanbuchus leverages two primary modules: a downloader module and a main module. In the following sections, we analyze the initial infection vector that was observed in an attack and both of the Matanbuchus modules. 

Initial infection vector

The threat actor performed the following hands-on-keyboard actions to deploy Matanbuchus:

  • The threat actor used QuickAssist (likely in conjunction with social engineering) to obtain access to the victim’s system.
  • The threat actor used the command-line to download and execute a malicious Microsoft Installer (MSI) package from gpa-cro[.]com.
  • The downloaded payload contained an executable named HRUpdate.exe, which sideloads a malicious DLL. The malicious DLL payload was the Matanbuchus downloader module.
  • The malicious DLL downloader downloaded the main module from: hxxps://mechiraz[.]com/cart/checkout/files/update_info.aspx

ThreatLabz assesses, with medium confidence, that the threat actor’s actions were intended to deploy ransomware to the victim’s organization.

Obfuscation

Both the Matanbuchus downloader and main modules use the following obfuscation methods:

  • Matanbuchus stores two arrays for decrypting strings at runtime. The first array contains the encrypted strings, while the second stores information for each string, including the index of the string in the first array and the string’s size. Matanbuchus utilizes the ChaCha20 stream cipher for decryption, using a shared key and nonce for all strings. These are stored as the first 44 bytes of the first array.
  • Matanbuchus resolves all necessary Windows API functions dynamically by using the MurmurHash algorithm.
  • Matanbuchus embeds multiple blocks of junk instructions in its codebase to hinder analysis, as shown in the figure below.

Example of junk instructions in the Matanbuchus main module code.

Figure 1: Example of junk instructions in the Matanbuchus main module code.

Downloader module


Anti-analysis

The downloader and main modules share most of the same anti-analysis features; however, the downloader includes an additional feature: long-running loops. These “busy” loops delay the downloader’s functionality for several minutes after initial execution, allowing it to evade behavioral analysis by sandboxes, which often have low analysis timeout values.

The figure below illustrates one of these long-running busy loops. 

Example of junk code and long-running busy loops in the Matanbuchus downloader module.

Figure 2: Example of junk code and long-running busy loops in the Matanbuchus downloader module.

Network communication

The downloader module contains an embedded, encrypted shellcode that downloads and executes the main module. The downloader leverages a known-plaintext attack technique to decrypt the shellcode via bruteforce. Matanbuchus initiates a loop that starts with the integer value 99999999. The integer is converted to an 8-byte string and prepended to a 24-byte hardcoded value to create a 32-byte ChaCha20 key. Matanbuchus then attempts to decrypt the shellcode with the ChaCha20 key and a hardcoded 12-byte nonce. Matanbuchus compares the result to the following 21 bytes, which correspond to the first 21 bytes of the shellcode, if decrypted properly.

The 21-byte known-plaintext string is shown below.

E9 A0 00 00 00 55 89 E5 6A 33 E8 00 00 00 00 83 04 24 05 CB 48

ANALYST NOTE: The ChaCha20 nonce field is set to the hardcoded array 01 02 03 04 05 06 07 08 09 10 11 12, while brute-forcing the shellcode data.

If the first 21 bytes do not match these values, the integer value is decremented by one and the loop is repeated.

The decrypted shellcode downloads the main module by sending an HTTPS GET request to a hardcoded command-and-control (C2) server and decrypts the payload received using the ChaCha20 stream cipher algorithm. The Python script below represents the decryption method for parsing and decrypting the downloaded payload.

 def decrypt_downloaded_payload(data: bytes) -> bytes:
       ”””
      Decrypts a downloaded payload from Matanbuchus. If first bytes are equal to 0xDEADBEEF then Matanbuchus writes the payload into disk.
       ”””
       decrypted_file = bytearray()
       payload_data = data[4:]
       key = payload_data[:32]
       nonce = payload_data[32: 44]
       encrypted_data = payload_data[44:]
       chunk_size = 0x2000
       state = 0
       for idx in range(0, len(encrypted_data), chunk_size):
           cipher = ChaCha20.new(key=key, nonce=nonce)
           cipher.seek(64 * state)
           cipher = cipher.decrypt(encrypted_data[idx: idx + 0x2000])
           decrypted_file.extend(cipher)
           state += 1
       return bytes(decrypted_file)


Main module


Persistence

Matanbuchus adds persistence to the compromised host by executing shellcode that is retrieved from the C2 server after the registration process (described later) is complete. Specifically, Matanbuchus generates a new file path and passes the value to the shellcode. The shellcode creates a new scheduled task with the name Update Tracker Task and a file path with the format below.

%WINDIR%\\SysWOW64\\msiexec.exe -z %Matanbuchus_path%

Matanbuchus generates the random file path with the following steps:

  • First, Matanbuchus creates a new directory under the Windows APPDATA folder. The name of the directory is derived from the volume serial number of the disk, as shown in Python below.
volume_serial_number = -1
directory_name = f"{volume_serial_number:x}{volume_serial_number >> 2:x}"
  • Then, Matanbuchus generates a new random filename with a 12-character lowercase alphabetical string.
  • Finally, Matanbuchus copies itself into the newly created directory using the randomly generated filename.

ANALYST NOTE: Matanbuchus creates a unique, per-host mutex to ensure single execution. The mutex name matches the name of the persistence directory, with the string sync prepended to it.

Configuration

The main module of Matanbuchus includes an embedded configuration blob, which is stored in an encrypted format. Upon execution, Matanbuchus decrypts the configuration blob using ChaCha20. The first 44 bytes of the configuration blob consist of the decryption key, followed by the nonce.

The decrypted configuration blob stores the following information:

  • A C2 URL along with a boolean value indicating if the network protocol is HTTP (false) or HTTPS (true).
  • A campaign ID stored in a UUID format.
  • An expiration date.

It is worth noting that Matanbuchus checks the expiration date only on execution and not at any other stage. Consequently, the compromised host might still communicate with the C2 server if the system was not restarted after the expiration date has passed. 

Network communication

Matanbuchus follows a network communication pattern similar to many other malware families. Matanbuchus starts by registering the compromised host with the C2 server and then requests a set of tasks from the server. If any tasks are available, Matanbuchus executes them and reports back any results.

The network communication pattern is illustrated in the figure below.

Matanbuchus network communication pattern.

Figure 3: Matanbuchus network communication pattern.

Matanbuchus supports three main request types. Each request type is assigned a unique ID, which appears at the beginning of each packet after serialization in a Protobuf data structure. These request ID values are listed in the table below.

Request Type

ID

Register bot

1

Get task(s)

2

Report task(s) result

3

Table 1: Matanbuchus request IDs.

Matanbuchus uses HTTP(S) for network communications with payloads that contain encrypted Protobufs. Matanbuchus encrypts each Protobuf using ChaCha20 by generating a random key and nonce that is prepended to the packet data. The structure below represents the layout of a network packet created by Matanbuchus.

#pragma pack(1)
struct network_packet
{
 uint8_t  key[32];
 uint8_t  nonce[12];
 uint32_t data_size;
 uint8_t  data[data_size];
};

The network packet data consists of a Protobuf with various message types.

Before requesting any tasks from the C2 server, Matanbuchus registers the compromised host by collecting and sending the following information.

  • Hostname and username.
  • Windows version.
  • Windows domain name.
  • A list of installed security products that includes:
    • Windows Defender
    • CrowdStrike Falcon
    • SentinelOne
    • Sophos EDR
    • Trellix
    • Cortex XDR
    • Bitdefender GravityZone EDR
  • Boolean value indicating if the compromised host is a Windows server.
  • Boolean value indicating if the compromised user has administrator privileges.
  • Boolean value indicating the Windows architecture (32/64-bit).
  • Campaign and bot IDs.

As soon as the registration process is complete, the following actions are taken.

  • Matanbuchus marks the compromised host as registered by creating a registry key under HKEY_CURRENT_USER\SOFTWARE\%volume_serial_number_based_ID% with the bot ID. Matanbuchus checks this registry path on each execution to verify if the host needs to be registered.
  • Matanbuchus adds persistence (as described in the Persistence section above).

After completing registration, Matanbuchus starts requesting tasks from the C2 server. The network commands supported by Matanbuchus are described in the table below.

ANALYST NOTE: Matanbuchus maps the network command IDs found in a packet to internal IDs embedded in the binary’s code. For clarity, both ID types are listed in the table below. 

Network Command ID

Internal ID

Description

1

0

Downloads and executes an EXE payload from an external URL. The payload can be executed in one of the following ways:

  • Write and execute the file on disk.
  • Inject the payload into a remote process. The parent process ID is not spoofed.
  • Inject the payload as before but spoof the parent process ID of the newly created process.

In addition, Matanbuchus can execute .NET payloads directly in memory.

2

1

Downloads and executes a DLL payload from an external URL. The payload can be executed in one of the following ways:

  • Execute the DLL payload with rundll32.
  • Execute the DLL payload with regsvr32.
  • Execute the DLL payload in a new thread of the current process.
  • Inject the DLL payload into a new process instance of msiexec. Instead of writing the payload directly to the remote process, Matanbuchus encrypts the DLL payload and injects a shellcode into the remote process. Next, the shellcode creates a named PIPE and uses it to transfer and decrypt the DLL payload in the remote process. The PIPE name format is \\\.\\pipe\\dll-%hex_encoded_PID_of_remote_process%.

3

2

Downloads and executes an MSI package from an external URL. The MSI file is written and executed to/from disk.

4

3

Executes a shellcode. Depending on the parameters passed, the shellcode is executed in one of the following ways:

  • In a new thread within the current Matanbuchus process.
  • Inject the downloaded shellcode into a new process instance of msiexec.

5

5

Collects the running processes on the compromised host. The list includes only the process names.

6

5

Collects the Windows services installed on the compromised host. The list includes the display names of the services.

7

5

Collects a list of software applications installed on the compromised host. The list includes the display names of the identified applications.

8

5

Gathers information on Windows cumulative updates installed on the compromised host.The list includes the name of each identified update, such as KB5066791.

9

6

Executes a system shell command using CMD.

10

6

Executes a system shell command using PowerShell.

11

6

Executes a system shell command using WMI.

12

3

Similar to network command ID 4, but the shellcode is executed within the context of the currently running thread, if a thread execution type is specified.

13

7

Terminates the Matanbuchus process.

14

4

Downloads and decompresses a ZIP archive from a remote URL. Matanbuchus runs any decompressed executable files.

Table 2: Matanbuchus network commands.

ANALYST NOTE: The reverse engineered Matanbuchus Protobuf structures are available here.

Notably, the payloads downloaded from external URLs may be encrypted. Matanbuchus determines if decryption is required by reading a boolean flag from the incoming Protobuf message. The payload decryption routine also uses ChaCha20, similar to the downloader module.

As a final step, Matanbuchus reports the result of each network command, including any output generated from the command. Each task report packet includes the bot ID, task IDs, and any command output (e.g., the result of executing a system shell command). If a task fails, Matanbuchus does not report the task to the C2 server.