Matanbuchus 3.0 Unleashes AstarionRAT via ClickFix Social Engineering and Silent MSI Installs
The Matanbuchus 3.0 loader has resurfaced, showcasing a sophisticated intrusion methodology that incorporates ClickFix social engineering, silent MSI installations, DLL sideloading, and a new remote access trojan named AstarionRAT. This highlights the…
The Matanbuchus 3.0 loader has resurfaced, showcasing a sophisticated intrusion methodology that incorporates ClickFix social engineering, silent MSI installations, DLL sideloading, and a new remote access trojan named AstarionRAT. This highlights the shift towards stealthier, multi-stage operations.
The attack begins with a ClickFix prompt that persuades users to execute a crafted command in their local console, sidestepping email and attachment filters. This command employs msiexec.exe with the /q (silent) flag to install a remote MSI package without visible UI, ensuring user actions remain undetected.
The MSI is retrieved from newly registered domains impersonating legitimate brands, using obfuscated URLs to complicate proxy and log analysis. Once executed, it deploys files under fake security directories, placing renamed legitimate binaries alongside malicious DLLs for sideloading.
Notable components include Zillya! Antivirus parts, Visual C++ runtimes, and the SystemStatus.dll , which serves as the embedded Matanbuchus 3.0 loader. The MSI uses a renamed 7-Zip executable to extract a password-protected archive containing the Zillya sideloading bundle.
Matanbuchus 3.0 is a rewritten loader marketed as high-end Malware-as-a-Service (MaaS) aimed at targeted operations. In observed intrusions, attackers quickly escalated privileges to domain controllers using PsExec and other tactics. The loader is filled with junk API calls and encrypted strings to hinder analysis.
The loader retrieves its core shellcode from an external file named INFO , encrypted with ChaCha20. It decrypts the shellcode, reconstructs a hardcoded HTTPS C2 URL, downloads the main Matanbuchus module, and decrypts it in segments. Before executing payloads, it enumerates processes for security software names to adapt its tactics accordingly.
Matanbuchus 3.0 is advertised at $10,000/month for the HTTPS version and $15,000 for the DNS version, with a new client and panel built from scratch.
AstarionRAT is a comprehensive remote access trojan with commands covering file management, process control, credential-backed logon, SOCKS5 tunneling, and reflective payload execution. It uses obfuscation techniques, such as arithmetic expressions with fixed constants, to evade detection.
Upon initial check-in, AstarionRAT builds a metadata structure encrypted with a hardcoded RSA public key. It communicates with C2 servers using HTTP GET and POST requests, embedding data in cookie values to mimic legitimate traffic.
Item Description
This command employs msiexec.exe with the /q (silent) flag to install a remote MSI package without visible UI, ensuring user actions remain undetected.
hxxp://binclloudapp[.]com/466943 ClickFix MSI delivery C2
hxxps://marle[.]io/check/updprofile.aspx Matanbuchus C2 - serves encrypted main module
www.ndibstersoft[.]com AstarionRAT C2
/intake/organizations/events?channel=app AstarionRAT beacon polling path
%APPDATA%\AegisLynx Cybernetics Ltd\AegisLynx Threat Fabric\AVU\ Matanbuchus MSI install path
%APPDATA%\DocuRay Technologies S.r.l\DocuRay PDF Professional\ZAVY\ Matanbuchus MSI install path
%APPDATA%\HelixShield Technologies ApS\HelixShield Adaptive Security\APS\ZAV\ Matanbuchus MSI install path
%LOCALAPPDATA%\Temp\ndvyxgdriggmarrf\ Stage 2 DLL sideloading package drop path
INFO SHA256: de81e2155d797ff729ed3112fd271aa2728e75fc71b023d0d9bb0f62663f33b3
SystemStatus.dll SHA256: 6ffae128e0dbf14c00e35d9ca17c9d6c81743d1fc5f8dd4272a03c66ecc1ad1f
jli.dll SHA256: 68858d3cbc9b8abaed14e85fc9825bc4fffc54e8f36e96ddda09e853a47e3e31
SySUpd SHA256: 03c624d251e9143e1c8d90ba9b7fa1f2c5dc041507fd0955bdd4048a0967a829
Reflective PE loader SHA256: 8e54cd12591d67dfbe72e94c1bde6059e1cba157e6786aec63f8f9e3c71fb925
Beacon.exe SHA256: eecc83add16f3d513a9701e9a646b1885014229ac6f86addd6b10afb64d1d2af
Updprofile.aspx SHA256: ea378496135318ac5ad667a032fa4a9686add9d27fe4a7c549c937611b5099e5
Based on reporting by GBHackers.
