Caminho

MITRE ATT&CK: S9016 View on attack.mitre.org

Aliases: VMDetectLoader, Caminho, Katz Stealer Loader

Malware type
downloader, loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:57:06

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

Caminho is a downloader that has been used by threat actors since at least 2025 to deliver various strains of malware such as XWorm.

Detection coverage

  • 1 YARA rules
  • 102 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Binary Padding (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_MAL_NET_Katz_Stealer_Loader_May25 (yara-rule)

Reports & references

  • cyble.com — Stealth In Layers Unmasking Loader In Targeted Email Campaigns (report)
  • ibm.com — Dcrat Presence Growing In Latin America (report)
  • zscaler.com — Blindeagle Targets Colombian Government Agency Caminho And Dcrat (report)
  • Palo Alto Unit 42 — Phantomvai Loader Delivers Infostealers (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Phantomvai (report)
  • MITRE ATT&CK — S9016 (report)

External references