catb

First seen
2022-10-01 00:00:00
Malware type
ransomware, dropper
Family
Malware family
Profile updated
2026-07-07 13:05:10

Targeted industries: retail-and-hospitality technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical

Context

CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distributed Transaction Coordinator (MSDTC) service—loading a malicious payload through DLL sideloading methods. The malware arrives in a two-stage dropper: the first DLL unpacks and launches the main payload (commonly named oci.dll), which subsequently encrypts files using hybrid RSA/AES cryptography. Unlike conventional ransomware, CatB does not rename files or distribute typical ransom notes; instead, it prepends the ransom message directly to the start of each encrypted file, making detection more difficult. Victims are instructed to contact the attackers via email (e.g., [email protected] or [email protected]), with the ransom demand escalating daily. Initial analysis suggests CatB may be a rebrand or evolution of Pandora ransomware, sharing various code artifacts and operational behavior.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Catb_Auto (yara-rule)

Reports & references

  • sentinelone.com — Chamelgang Attacking Critical Infrastructure With Ransomware (report)
  • ransomlook.io — Catb (report)
  • sentinelone.com — Decrypting Catb Ransomware Analyzing Their Latest Attack Methods (report)
  • fortinet.com — Ransomware Roundup Catb Ransomware (report)
  • vmray.com — Catb Ransomware A New Threat Exploiting Dll Side Loading (report)
  • cymulate.com — Catb Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Catb (report)
  • hitcon.org — Unmasking%20Camofei An%20In Depth%20Analysis%20Of%20An%20Emerging%20Apt%20Group%20Focused%20On%20Healthcare%20Sectors%20In%20East%20Asia (report)
  • minerva-labs.com — New Catb Ransomware Employs 2 Year Old Dll Hijacking Technique To Evade Detection (report)
  • vmray.com — Catb Ransomware A New Threat Exploiting Dll Side Loading (report)
  • stillu.cc — 2023 08 Unmasking%20Camofei (report)

External references