Skip to content
Matanbuchus 3.0 Malware Analysis: New Features and Ransomware Links

Matanbuchus 3.0 Malware Analysis: New Features and Ransomware Links

First seen 4 Dec 2025, 02:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Matanbuchus 3.0, a C++-based downloader offered as Malware-as-a-Service since 2020, was identified in July 2025. This version introduces Protobuf-based serialization, ChaCha20 encryption, and enhanced anti-analysis techniques. It has been linked to ransomware operations and allows threat actors to deploy additional payloads and execute shell commands.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Matanbuchus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed