Threat Advisory

ClickFix-Driven Malicious Campaign Deploying Matanbuchus and AstarionRAT

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A malicious campaign that relies on user deception and staged malware deployment to gain and maintain unauthorized access. Instead of exploiting a traditional software vulnerability, the attackers manipulate human behavior through the ClickFix technique, which tricks users into executing commands under false pretenses. This approach highlights the continued effectiveness of social engineering as an initial access vector, particularly in environments where technical defenses may be strong but user awareness varies. Following successful execution, the attack chain introduces Matanbuchus, a loader designed to establish a foothold and retrieve additional payloads. The loader’s modular nature allows operators to adapt the campaign dynamically without requiring repeated user interaction. Ultimately, the infection progresses to AstarionRAT, a remote access trojan enabling persistent control and deeper post-compromise activity. The campaign exemplifies modern threat tradecraft, where psychological manipulation, MaaS ecosystems, and multi-stage payload delivery combine to create resilient and stealthy intrusions that challenge conventional detection strategies.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A malicious campaign that relies on user deception and staged malware deployment to gain and maintain unauthorized access. Instead of exploiting a traditional software vulnerability, the attackers manipulate human behavior through the ClickFix technique, which tricks users into executing commands under false pretenses. This approach highlights the continued effectiveness of social engineering as an initial access vector, particularly in environments where technical defenses may be strong but user awareness varies. Following successful execution, the attack chain introduces Matanbuchus, a loader designed to establish a foothold and retrieve additional payloads. The loader’s modular nature allows operators to adapt the campaign dynamically without requiring repeated user interaction. Ultimately, the infection progresses to AstarionRAT, a remote access trojan enabling persistent control and deeper post-compromise activity. The campaign exemplifies modern threat tradecraft, where psychological manipulation, MaaS ecosystems, and multi-stage payload delivery combine to create resilient and stealthy intrusions that challenge conventional detection strategies.[emaillocker id="1283"]

The technical examination reveals a multi-layered intrusion sequence engineered for stealth, adaptability, and operational longevity. After user interaction triggers execution via ClickFix, Matanbuchus functions as the primary loader, initiating the malicious runtime and acting as a delivery mechanism for secondary components. Its role centers on downloading, decrypting, and injecting payloads directly into memory, thereby minimizing forensic artifacts on disk. This memory-resident behavior, combined with encrypted network communications, complicates signature-based detection and delays incident response visibility. The loader’s modular architecture enables attackers to update tooling or alter payloads without re-establishing initial access, enhancing campaign flexibility. The deployment of AstarionRAT signifies the shift from initial compromise to active post-exploitation. The RAT provides capabilities such as host reconnaissance, credential harvesting, proxying, and network scanning, allowing operators to map the environment and identify opportunities for lateral movement. Encrypted command-and-control channels further obscure malicious traffic within normal network flows. Overall, the attack chain demonstrates how loaders and RATs operate synergistically: the loader ensures persistence and payload management, while the RAT delivers interactive control and intelligence gathering.

This campaign underscores the evolving nature of intrusion methodologies, where social engineering, loaders, and remote access tools form a cohesive attack strategy. By leveraging user-driven execution rather than exploit-based compromise, the attackers reduce dependency on unpatched vulnerabilities and instead capitalize on trust and interface manipulation. The use of a loader introduces durability and scalability, enabling rapid payload changes and sustained operations across multiple victims. The presence of a RAT elevates the risk profile, granting adversaries persistent, interactive control capable of facilitating data theft, credential abuse, and network expansion. From a defensive perspective, the findings emphasize the necessity of layered security controls that extend beyond vulnerability management. User awareness training, behavioral detection, memory analysis, and network anomaly monitoring become critical in identifying and disrupting such threats. The campaign illustrates how modern attackers blend psychological tactics with modular malware ecosystems to bypass conventional safeguards.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Execution T1204.004 User Execution Malicious Copy and Paste
T1059.003 Command and Scripting Interpreter Windows Command Shell
T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027 Obfuscated Files or Information
T1620 Reflective Code Loading
Credential Access T1555 Credentials from Password Stores
T1003 OS Credential Dumping
Discovery T1082 System Information Discovery
T1046 Network Service Discovery
Command and Control T1071.001 Application Layer Protocol Web Protocols
T1095 Non-Application Layer Protocol

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/matanbuchus-3-0-returns-with-clickfix-social-engineering/

https://www.huntress.com/blog/clickfix-matanbuchus-astarionrat-analysis

[/emaillocker]
crossmenu