Technical Analysis of Matanbuchus 3.0
Essential information
- Published
- 03/12/2025 08:47
- Modified
- 21/12/2025 18:18
- Tags
- 2025-12-03 backdoor chacha20 downloader matanbuchus netsupport rat ransomware rhadamanthys
- Related entities
- 5 observables, 20 techniques (mitre), 1 malware, 2 others
Description
Matanbuchus, a C++ malicious downloader offered as Malware-as-a-Service since 2020, has evolved to version 3.0. It comprises a downloader and main module, utilizing obfuscation techniques like junk code, encrypted strings, and API hashing. The malware implements anti-analysis features, including an expiration date and persistence via scheduled tasks. It communicates using encrypted Protobufs over HTTP(S), supporting various commands for payload execution, data collection, and system manipulation. Matanbuchus has been associated with ransomware operations and used to distribute other malware like Rhadamanthys and NetSupport RAT.