Catchamas
MITRE ATT&CK: S0261 View on attack.mitre.org
Aliases: Catchamas
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-08-18 08:36:41
- Profile updated
- 2026-07-07 12:54:28
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
Catchamas is a Windows Trojan that steals information from compromised systems.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Catchamas (S0261). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | ÐÑполниÑелÑнÑй лиÑÑ â13408724-25.scr | 2026-08-18 | 2 |
Detection coverage
- 1 YARA rules
- 150 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- Keylogging (attack-pattern)
- Windows Service (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Clipboard Data (attack-pattern)
- Local Data Staging (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Application Window Discovery (attack-pattern)
- Screen Capture (attack-pattern)
Used by threat actors
- Thrip (threat-actor)
Detection rules
- MALPEDIA_Win_Catchamas_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Thrip Hits Satellite Telecoms Defense Targets (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Catchamas (report)
- MITRE ATT&CK — S0261 (report)
- web.archive.org — 2018 040209 1742 99 (report)