catb
- First seen
- 2022-10-01 00:00:00
- Malware type
- ransomware, dropper
- Family
- Malware family
- Profile updated
- 2026-07-07 13:05:10
Targeted industries: retail-and-hospitality technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical
Context
CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distributed Transaction Coordinator (MSDTC) service—loading a malicious payload through DLL sideloading methods. The malware arrives in a two-stage dropper: the first DLL unpacks and launches the main payload (commonly named oci.dll), which subsequently encrypts files using hybrid RSA/AES cryptography. Unlike conventional ransomware, CatB does not rename files or distribute typical ransom notes; instead, it prepends the ransom message directly to the start of each encrypted file, making detection more difficult. Victims are instructed to contact the attackers via email (e.g., [email protected] or [email protected]), with the ransom demand escalating daily. Initial analysis suggests CatB may be a rebrand or evolution of Pandora ransomware, sharing various code artifacts and operational behavior.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Catb_Auto (yara-rule)
Reports & references
- sentinelone.com — Chamelgang Attacking Critical Infrastructure With Ransomware (report)
- ransomlook.io — Catb (report)
- sentinelone.com — Decrypting Catb Ransomware Analyzing Their Latest Attack Methods (report)
- fortinet.com — Ransomware Roundup Catb Ransomware (report)
- vmray.com — Catb Ransomware A New Threat Exploiting Dll Side Loading (report)
- cymulate.com — Catb Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Catb (report)
- hitcon.org — Unmasking%20Camofei An%20In Depth%20Analysis%20Of%20An%20Emerging%20Apt%20Group%20Focused%20On%20Healthcare%20Sectors%20In%20East%20Asia (report)
- minerva-labs.com — New Catb Ransomware Employs 2 Year Old Dll Hijacking Technique To Evade Detection (report)
- vmray.com — Catb Ransomware A New Threat Exploiting Dll Side Loading (report)
- stillu.cc — 2023 08 Unmasking%20Camofei (report)