home.social

#matanbuchus — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #matanbuchus, aggregated by home.social.

fetched live
  1. 🎯 Threat Intelligence
    ===================

    Executive summary: GrayBravo (formerly TAG-150) is a rapidly evolving threat actor observed since at least March 2025. Insikt Group attributes a multi-tiered malware ecosystem to GrayBravo, centered on the CastleLoader loader and multiple downstream payloads, and identifies four discrete activity clusters with unique TTPs and victim profiles.

    Technical details: The actor developed multiple custom families including CastleLoader, CastleBot and the recently documented CastleRAT. Two tracked clusters are notable: TAG-160 (logistics impersonation, abuse of freight-matching platforms, ClickFix-based phishing delivery) and TAG-161 (Booking.com impersonation, ClickFix delivery of CastleLoader and Matanbuchus, and bespoke phishing email management tooling). The reporting links an online persona "Sparja" on Exploit Forums to related activity via historical panel analysis. The report references an Appendix H containing a full IoC set.

    Analysis: The division into four activity clusters with distinct victimology and tooling supports the assessment that GrayBravo operates a malware-as-a-service (MaaS) model. The proliferation of CastleLoader admin panels and diversified second-stage payloads are consistent with service-oriented distribution. The actor leverages legitimate internet services (LISs) such as Pastebin and freight-matching platforms to host lures or staging material and to obfuscate delivery chains.

    🔹 Attack Chain Analysis
    • Initial Access / Phishing: Targets receive spoofed emails impersonating logistics firms or Booking.com, leveraging ClickFix lure delivery.
    • Download / Delivery: Victims are directed to benign-appearing resources or abused LISs to retrieve CastleLoader.
    • Execution / Payloads: CastleLoader deploys second-stage payloads including info stealers and RATs such as Matanbuchus and CastleRAT.
    • C2 / Infrastructure: Activity uses multi-tiered, actor-controlled infrastructure with numerous administration panels and supporting services.

    Detection: The report recommends applying updated detection content (YARA, Snort, Sigma) targeting loader and second-stage behaviors, flagging anomalous connections to unusual LISs, and monitoring for indicators listed in Appendix H.

    Mitigation (as reported): Insikt Group advises blocking IPs/domains associated with the loaders and payloads, increasing email filtering, and implementing data exfiltration monitoring. Specific technical indicators and lists are provided in the report appendices.

    References: See Insikt Group report (analysis cutoff 2025-11-10) and Appendix H for IoCs and full detection artifacts.

    🔹 GrayBravo #CastleLoader #ClickFix #Matanbuchus #MaaS

    🔗 Source: recordedfuture.com/research/gr

  2. Security researchers reveal campaign distributing malware through Microsoft Teams

    Attack:
    - Attackers impersonate IT helpdesk
    - Tricks users into downloading the Matanbuchus loader
    - The loader in turn can collect information, run commands, and download other malware

    #cybersecurity #socialengineering #Matanbuchus

    bleepingcomputer.com/news/secu

  3. Security researchers reveal campaign distributing malware through Microsoft Teams

    Attack:
    - Attackers impersonate IT helpdesk
    - Tricks users into downloading the Matanbuchus loader
    - The loader in turn can collect information, run commands, and download other malware

    #cybersecurity #socialengineering #Matanbuchus

    bleepingcomputer.com/news/secu

  4. Security researchers reveal campaign distributing malware through Microsoft Teams

    Attack:
    - Attackers impersonate IT helpdesk
    - Tricks users into downloading the Matanbuchus loader
    - The loader in turn can collect information, run commands, and download other malware

    #cybersecurity #socialengineering #Matanbuchus

    bleepingcomputer.com/news/secu

  5. Security researchers reveal campaign distributing malware through Microsoft Teams

    Attack:
    - Attackers impersonate IT helpdesk
    - Tricks users into downloading the Matanbuchus loader
    - The loader in turn can collect information, run commands, and download other malware

    #cybersecurity #socialengineering #Matanbuchus

    bleepingcomputer.com/news/secu