#MATA

Malware/Tool

2020-07-22 • MATA: Multi-platform targeted malware framework

MATA is an advanced cross-platform malware framework associated with Lazarus and available for Windows, Linux, and macOS. Its architecture includes loaders and payloads with full backdoor capabilities, while plugins support reconnaissance, command-and-control communication, and file searching, manipulation, modification, and transfer. A 2022–2023 campaign targeted Eastern European oil, gas, and defense companies through spear-phishing documents that fetched a CVE-2021-26411 exploit, followed by loader, trojan, and stealer chains. Attackers also abused centralized security-management systems for distribution, reached Unix-like hosts, and used a USB propagation module to bridge air-gapped networks. MATA has additionally delivered TFlower and VHD ransomware.

Tagged Reports

« Back