Matanbuchus 3.0 Malware Analysis: New Features and Ransomware Links
Article Content
Browse articles
Matanbuchus 3.0, a C++-based downloader offered as Malware-as-a-Service since 2020, was identified in July 2025. This version introduces Protobuf-based serialization, ChaCha20 encryption, and enhanced anti-analysis techniques. It has been linked to ransomware operations and allows threat actors to deploy additional payloads and execute shell commands.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Matanbuchus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ClickFix Scam: Users Self-Install Malware via Social Engineering The ClickFix scam has emerged as a significant threat, tricking users into executing malicious PowerShell scripts under the guise of fixing technical issues. Threat actors, including TA571 and the ClearFake activity cluster, utilize social engineering tactics such as fake CAPTCHAs and browser error messages to prompt…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…