TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers use Microsoft Teams to spread Matanbuchus malware

Akinola Ajibola by Akinola Ajibola
July 17, 2025
in Security
Share on FacebookShare on Twitter

Morphisec said on Wednesday that a new version of the Matanbuchus malware loader is being distributed by phishing through Microsoft Teams, confirming that the well‑known Malware‑as‑a‑Service product has quietly evolved into a far more elusive threat. Researchers analysing the samples call the build “Matanbuchus 3.0,” describing it as a near‑total rewrite that relies on deeper in‑memory execution, heavier obfuscation and a revamped command‑and‑control protocol to keep detections low.

An advertisement posted to a Russian‑language crime forum on 7 July 2025 pitches the update at US $10,000 per month for the HTTPS flavour and US $15,000 for a DNS‑tunnel variant, up from the original 2021 rental fee of $2,500. Morphisec notes that it intercepted the loader in the wild days before the ad appeared, proof that the new build had already been circulating in trusted criminal circles.

Matanbuchus has served as a conduit for ransomware operators and red‑team toolkits since 2021, ferrying Cobalt Strike beacons, QakBot, DanaBot and other second‑stage implants that often precede file‑encryption attacks. Its delivery methods have morphed from malicious MSI installers and drive‑by downloads on compromised websites to Google Drive links, malvertising and, most recently, socially engineered Microsoft Teams calls aimed at selected employees of high‑value companies.

In one incident this month a Morphisec customer received an external Teams call from attackers posing as an IT help‑desk crew. The callers persuaded staff to open Microsoft’s Quick Assist tool for remote troubleshooting, then walked them through a single‑line PowerShell command that fetched a ZIP archive. The bundle held a renamed Notepad++ updater (GUP.exe), a tampered XML configuration file and a malicious side‑loaded DLL that instantiated the Matanbuchus loader—an approach that neatly bypassed email filtering and endpoint detection.

Version 3.0’s feature list reads like a catalogue of modern evasion: indirect system‑call tricks, Windows Management Instrumentation queries, support for WQL, CMD and PowerShell reverse shells, and the ability to drop or inject EXE, DLL, MSI or raw shellcode payloads. The loader watches running processes for security tools, checks its privilege level, and talks to its C2 over an encrypted channel before scheduling follow‑on tasks via COM object abuse—a tactic Morphisec’s Michael Gorelik says “manipulates the ITaskService in a way that most EDR engines simply don’t log.”

Once installed, Matanbuchus exfiltrates hardware and software inventories, pulls down additional payloads and establishes persistence, often by side‑loading legitimate Windows binaries such as regsvr32, rundll32 or msiexec or by carving out hollowed host processes. Those capabilities, combined with pricing that rivals top loader families like Bumblebee, position Matanbuchus 3.0 as a premium launchpad for ransomware crews including Black Basta, which already favour Teams‑based social engineering.

Security analysts say the rise of loaders that masquerade as business‑collaboration traffic—Zoom phishing and Slack token theft have also increased—underscores the need for strict verification policies around external chat requests and stronger monitoring of remote‑assist tools. As Gorelik puts it, “Matanbuchus 3.0 shows how little code attackers now need to touch disk before your EDR rings an alarm—by the time you hear it, the beacon is already calling home.”

Related Posts:

  • Microsoft Teams
    Microsoft Teams Vulnerability Exposes User Systems
  • ms teams
    KongTuke Hackers Exploits Microsoft Teams To Breach…
  • Chinaflag_computercode_MykhailoPolenok-AlamyStockPhoto
    New Malware Deployed By Chinese APT To Retain Access…
  • google-ads-scaled
    Attackers & Hackers Use Google Ads & Claude.AI Chats…
  • Robotics
    Nigeria Ranked As Africa’s Second Most Cyber-secure…
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • handala hackers
    FBI Warns of Handala Hackers Using Telegram for Malware
  • ms teams1
    Microsoft Confirms Degrading Service Outage On Teams

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: hackersmalwareMatanbuchus malwaremicrosoft teams
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Amazon Raised Anthropic AI Security Concerns Before US Crackdown on Fable 5 and Mythos 5 June 14, 2026
  • Europe Calls Anthropic AI Ban a ‘Wake-Up Call’ as US Shuts Off Access to Fable 5 and Mythos 5 June 14, 2026
  • US Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Over National Security Concerns June 14, 2026
  • Elon Musk Hits $1.1 Trillion as SpaceX Surpasses $2 Trillion Valuation June 13, 2026
  • SpaceX Prices Record $75 Billion IPO as Elon Musk Nears Trillionaire Status June 12, 2026
  • DoorDash Launches AI Chatbot for Food Orders June 12, 2026
  • Pool Launches App That Makes Screenshots More Useful June 12, 2026
  • Deezer Launches Tool to Detect AI-Generated Music June 12, 2026
  • Coinbase Introduces Platform for Agents to Trade Assets and Buy Premium Insights June 12, 2026
  • Meta Expands Edits App With AI Features and Desktop Access June 12, 2026
  • Ready-made LMS and custom development. Pros and cons of each path. June 11, 2026
  • TELCOs Pay 75 Million Users For Poor Network Service June 10, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.