TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers use Microsoft Teams to spread Matanbuchus malware

Akinola Ajibola by Akinola Ajibola
July 17, 2025
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Morphisec said on Wednesday that a new version of the Matanbuchus malware loader is being distributed by phishing through Microsoft Teams, confirming that the well‑known Malware‑as‑a‑Service product has...
  • Researchers analysing the samples call the build “Matanbuchus 3.0,” describing it as a near‑total rewrite that relies on deeper in‑memory execution, heavier obfuscation and a revamped command‑and‑control...
  • An advertisement posted to a Russian‑language crime forum on 7 July 2025 pitches the update at US $10,000 per month for the HTTPS flavour and US $15,000 for a DNS‑tunnel variant,...

Morphisec said on Wednesday that a new version of the Matanbuchus malware loader is being distributed by phishing through Microsoft Teams, confirming that the well‑known Malware‑as‑a‑Service product has quietly evolved into a far more elusive threat. Researchers analysing the samples call the build “Matanbuchus 3.0,” describing it as a near‑total rewrite that relies on deeper in‑memory execution, heavier obfuscation and a revamped command‑and‑control protocol to keep detections low.

An advertisement posted to a Russian‑language crime forum on 7 July 2025 pitches the update at US $10,000 per month for the HTTPS flavour and US $15,000 for a DNS‑tunnel variant, up from the original 2021 rental fee of $2,500. Morphisec notes that it intercepted the loader in the wild days before the ad appeared, proof that the new build had already been circulating in trusted criminal circles.

Matanbuchus has served as a conduit for ransomware operators and red‑team toolkits since 2021, ferrying Cobalt Strike beacons, QakBot, DanaBot and other second‑stage implants that often precede file‑encryption attacks. Its delivery methods have morphed from malicious MSI installers and drive‑by downloads on compromised websites to Google Drive links, malvertising and, most recently, socially engineered Microsoft Teams calls aimed at selected employees of high‑value companies.

Also worth reading
Attackers & Hackers Use Google Ads & Claude.AI Chats To Spread Mac Malware KongTuke Hackers Exploits Microsoft Teams To Breach Companies Microsoft Teams Unveils Major Redesign Hackers Abuse Microsoft Password Reset to Steal Data Microsoft Confirms Degrading Service Outage On Teams Microsoft Retires Teams’ Together Mode to Simplify Video and Boost Performance

In one incident this month a Morphisec customer received an external Teams call from attackers posing as an IT help‑desk crew. The callers persuaded staff to open Microsoft’s Quick Assist tool for remote troubleshooting, then walked them through a single‑line PowerShell command that fetched a ZIP archive. The bundle held a renamed Notepad++ updater (GUP.exe), a tampered XML configuration file and a malicious side‑loaded DLL that instantiated the Matanbuchus loader—an approach that neatly bypassed email filtering and endpoint detection.

Version 3.0’s feature list reads like a catalogue of modern evasion: indirect system‑call tricks, Windows Management Instrumentation queries, support for WQL, CMD and PowerShell reverse shells, and the ability to drop or inject EXE, DLL, MSI or raw shellcode payloads. The loader watches running processes for security tools, checks its privilege level, and talks to its C2 over an encrypted channel before scheduling follow‑on tasks via COM object abuse—a tactic Morphisec’s Michael Gorelik says “manipulates the ITaskService in a way that most EDR engines simply don’t log.”

Once installed, Matanbuchus exfiltrates hardware and software inventories, pulls down additional payloads and establishes persistence, often by side‑loading legitimate Windows binaries such as regsvr32, rundll32 or msiexec or by carving out hollowed host processes. Those capabilities, combined with pricing that rivals top loader families like Bumblebee, position Matanbuchus 3.0 as a premium launchpad for ransomware crews including Black Basta, which already favour Teams‑based social engineering.

Security analysts say the rise of loaders that masquerade as business‑collaboration traffic—Zoom phishing and Slack token theft have also increased—underscores the need for strict verification policies around external chat requests and stronger monitoring of remote‑assist tools. As Gorelik puts it, “Matanbuchus 3.0 shows how little code attackers now need to touch disk before your EDR rings an alarm—by the time you hear it, the beacon is already calling home.”

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • ms teams
    KongTuke Hackers Exploits Microsoft Teams To Breach…
  • Chinaflag_computercode_MykhailoPolenok-AlamyStockPhoto
    New Malware Deployed By Chinese APT To Retain Access…
  • google-ads-scaled
    Attackers & Hackers Use Google Ads & Claude.AI Chats…
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • claude code1
    Leaked & Exploited Claude Code Distributes…
  • ms teams1
    Microsoft Confirms Degrading Service Outage On Teams
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: hackersmalwareMatanbuchus malwaremicrosoft teams
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Meta Revenue Beats But AI Spending And Legal Costs Hit Profit July 29, 2026
  • Microsoft Cloud Growth Jumps As Azure Gives AI Spending A Better Answer July 29, 2026
  • Russia Charges Telegram Founder Pavel Durov With Facilitating Terrorism July 29, 2026
  • Google DeepMind Reportedly Breaks Up The AlphaFold Team July 29, 2026
  • Huawei Pushes Enterprise AI Solutions In South Africa July 29, 2026
  • GoLemon Stops Taking Orders As Lagos Grocery Delivery Startup Winds Down July 29, 2026
  • Ethiopia Banking Summit Puts Digital Finance At The Centre Of Reform July 29, 2026
  • Clydestone Ghana Sues MTN Over Mobile Money IP Dispute July 29, 2026
  • DoorDash Launches DoorDash Air As It Builds Its Own Delivery Drones July 29, 2026
  • SK Hynix Posts Record AI Memory Profit But Shares Fall On High Expectations July 29, 2026
  • Cyera Buys Oasis Security For $1B As AI Agents Create New Identity Risks July 29, 2026
  • OpenAI Says Rogue Agent Also Breached Other Services After Hugging Face Incident July 29, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.