Matanbuchus 3.0, a premium malware-as-a-service loader attributed to developer BelialDemon, is being used in social-engineering intrusions that begin with ClickFix prompts or Microsoft Teams vishing and Quick Assist abuse. In one investigated operation, a victim was induced to run a malicious MSI that deployed the loader through DLL sideloading; the infection chain ultimately installed the previously undocumented AstarionRAT. Operators then moved rapidly toward Windows servers and domain controllers using PsExec, created rogue accounts, and staged Microsoft Defender exclusions—activity consistent with preparation for ransomware deployment or data theft.
The C++ rewrite replaces older Matanbuchus mechanisms with encrypted Protobuf command-and-control over HTTP(S), ChaCha20-protected strings and shellcode, dynamic Windows API resolution, and extensive security-product discovery. Its two-module architecture uses anti-analysis delays, junk code, a Heaven’s Gate transition to evade WoW64 EDR hooks, and multiple DLL-sideloading stages; it can establish persistence through the Update Tracker Task scheduled task and execute payloads from disk or memory. Organizations should prioritize user resistance to ClickFix and remote-support impersonation, restrict and monitor Quick Assist and PsExec, investigate suspicious MSI and DLL-sideloading activity, and alert on Defender exclusion changes, anomalous scheduled tasks, and unauthorized domain-account creation.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
The operators returned the next day and, within roughly 40 minutes, used PsExec to move toward a Windows Server and two domain controllers. They created rogue accounts and staged files under a Microsoft Defender exclusion, but were disrupted before reaching their final objective.
Huntress responded to a hands-on intrusion that began when a ClickFix lure convinced a user to silently install a malicious MSI. The chain used Zillya AVCore.exe DLL sideloading to deploy Matanbuchus 3.0 and ultimately installed the previously undocumented AstarionRAT implant.
BelialDemon advertised the rewritten Matanbuchus 3.0 service, offering an HTTPS variant for about $10,000 monthly and a DNS variant for about $15,000 monthly.
Matanbuchus activity entered a brief operational hiatus around May 2025 before the developer resumed promotion of a new version.
A threat actor using the name BelialDemon advertised the C++ Matanbuchus malware loader on Russian-speaking/underground cybercrime forums as a malware-as-a-service offering.
In a separate observed delivery chain, an actor obtained access through Quick Assist, likely using social engineering, then downloaded and ran a malicious MSI containing HRUpdate.exe. HRUpdate.exe sideloaded a malicious DLL that acted as the Matanbuchus downloader, and researchers assessed the activity as likely intended to culminate in ransomware deployment.
The domain binclloudapp.com, later used as a remote MSI source in a ClickFix delivery chain, was newly registered.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourcezscaler.com
Open sourcehuntress.com
Open sourcemorphisec.com
Open sourcecyberark.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.