Caminho
MITRE ATT&CK: S9016 View on attack.mitre.org
Aliases: VMDetectLoader, Caminho, Katz Stealer Loader
- Malware type
- downloader, loader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:57:06
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Context
Caminho is a downloader that has been used by threat actors since at least 2025 to deliver various strains of malware such as XWorm.
Detection coverage
- 1 YARA rules
- 102 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Process Hollowing (attack-pattern)
- Binary Padding (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
- APT-C-36 (threat-actor)
Detection rules
- SIGNATURE_BASE_MAL_NET_Katz_Stealer_Loader_May25 (yara-rule)
Reports & references
- cyble.com — Stealth In Layers Unmasking Loader In Targeted Email Campaigns (report)
- ibm.com — Dcrat Presence Growing In Latin America (report)
- zscaler.com — Blindeagle Targets Colombian Government Agency Caminho And Dcrat (report)
- Palo Alto Unit 42 — Phantomvai Loader Delivers Infostealers (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Phantomvai (report)
- MITRE ATT&CK — S9016 (report)