Friday, September 11, 2026

Microsoft Teams Exploited to Deliver Matanbuchus Ransomware Payload

A sophisticated cyberattack campaign has emerged targeting organizations through Microsoft Teams impersonation, delivering the updated Matanbuchus 3.0 malware loader that serves as a precursor to ransomware deployment.

Security researchers at Morphisec have identified instances where attackers successfully compromised systems by impersonating IT helpdesk personnel during external Teams calls, ultimately leading to the execution of malicious scripts that deployed the advanced malware loader.

The attack methodology involves social engineering tactics where cybercriminals contact victims through Microsoft Teams, presenting themselves as legitimate IT support staff.

During these fraudulent interactions, attackers guide unsuspecting employees to activate Quick Assist and execute PowerShell scripts that initiate the malware deployment process.

This technique represents a significant evolution in attack vectors, leveraging the trust associated with familiar business communication platforms to bypass traditional security measures.

Matanbuchus Ransomware
Infection Chain

Enhanced Malware-as-a-Service Platform

Matanbuchus has evolved significantly since its initial deployment in 2021, now operating as a sophisticated Malware-as-a-Service platform with the recently released version 3.0 commanding prices of $10,000 for HTTP variants and $15,000 for DNS variants on underground markets.

The malware’s primary function involves establishing initial system compromise and facilitating the deployment of secondary payloads, including ransomware, making it a critical component in multi-stage attack chains.

The updated version incorporates advanced obfuscation techniques utilizing Salsa20 encryption with 256-bit keys, replacing the previously used RC4 algorithm.

This enhancement significantly improves the malware’s ability to evade detection while maintaining communication with command and control servers.

The loader now employs MurmurHash3 algorithms for API resolution, demonstrating the developers’ commitment to staying ahead of security detection mechanisms.

Persistence mechanisms have been substantially refined, with the malware now creating scheduled tasks through sophisticated COM manipulation and shellcode injection techniques.

The loader generates unique identifiers based on system volume serial numbers and establishes registry entries that enable continuous communication with command and control infrastructure.

This persistence strategy ensures the malware can maintain its foothold on compromised systems even after system reboots or security scans.

Advanced Technical Capabilities

The malware demonstrates sophisticated system reconnaissance capabilities, collecting extensive information about the compromised environment including security controls, system configurations, and installed applications.

Matanbuchus 3.0 specifically identifies the presence of major endpoint detection and response solutions including Windows Defender, CrowdStrike Falcon, SentinelOne, Sophos EDR, Trellix, Cortex XDR, BitDefender GravityZone EDR, ESET Enterprise Inspector, and Symantec Endpoint Detection and Response.

This intelligence gathering enables the malware to adapt its execution strategies based on the security stack present on the target system.

The loader can execute various payload types including MSI installers, DLL files, executables, and shellcode, with support for both direct execution and process hollowing techniques.

The malware impersonates legitimate applications such as Skype Desktop (version 8.69.0.77) to blend with normal network traffic during command and control communications.

Command execution capabilities include direct CMD and PowerShell command execution, WQL query support for system information gathering, and the ability to install MSI packages with administrative privileges.

The loader utilizes indirect system calls to evade detection by security solutions that monitor direct API calls, demonstrating advanced evasion techniques typically associated with state-sponsored malware.

Matanbuchus Ransomware
notepad GUP updater

The delivery mechanism involves cybersquatting techniques, utilizing domains such as notepad-plus-plu[.]org (missing the ‘s’ from the legitimate notepad-plus-plus.org) to host malicious update packages.

These packages contain legitimate Notepad++ updater components alongside malicious DLL files that sideload the Matanbuchus payload.

The attack chain begins with PowerShell scripts that download and execute these packages, establishing the initial compromise vector that enables further malicious activity.

Indicators of Compromise (IOCs)

Hash/URLDescription
94.159.113[.]33 – fixuplink[.]com [RU]Command and Control Server
bretux[.]comMalicious Domain
nicewk[.]comCommand and Control Domain
emorista[.]orgMalicious Domain
notepad-plus-plu[.]orgMalicious Update Location
da9585d578f367cd6cd4b0e6821e67ff02eab731ae78593ab69674f649514872libcurl.dll (SHA256)
2ee3a202233625cdcdec9f687d74271ac0f9cb5877c96cf08cf1ae88087bec2elibcurl.dll (SHA256)
19fb41244558f3a7d469b79b9d91cd7d321b6c82d1660738256ecf39fe3c8421libcurl.dll (SHA256)
211cea7a5fe12205fee4e72837279409ace663567c5b8c36828a3818aabef456libcurl.dll (SHA256)
0f41536cd9982a5c1d6993fac8cd5eb4e7f8304627f2019a17e1aa283ac3f47clibcurl.dll (SHA256)
EventLogBackupTaskScheduled Task Name

Get Free Ultimate SOC Requirements Checklist Before you build, buy, or switch your SOC for 2025 - Download Now

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News