Threat actors are utilizing the Matanbuchus downloader to deliver ransomware and maintain persistence within compromised systems. This malicious downloader is part of a broader trend in cyberattacks targeting various…
Matanbuchus 3.0, a C++-based downloader offered as Malware-as-a-Service since 2020, was identified in July 2025. This version introduces Protobuf-based serialization, ChaCha20 encryption, and enhanced anti-analysis…
The Matanbuchus downloader malware is evolving by frequently changing its components to evade antivirus defenses. This adaptability poses challenges for cybersecurity measures aimed at detecting and neutralizing the…
A new malware campaign named 'Crescent Harvest' has been identified, targeting supporters of protests in Iran. The malware specifically affects Farsi-speaking users seeking information about the demonstrations,…
GrayBravo, previously known as TAG-150, has expanded its CastleLoader malware deployment across four distinct threat activity clusters since March 2025. The malware targets industries such as logistics and hospitality,…
Matanbuchus 3.0, a Malware-as-a-Service loader, has re-emerged in February 2026 after nearly a year of inactivity. This version introduces ClickFix social engineering tactics and silent MSI installations to deploy…