Brazilian Caminho Loader Employs LSB Steganography and Fileless Execution to Deliver Multiple Malware Families Across South America, Africa, and Eastern Europe
ID: 49509b9f-5200-51fa-9aab-30ac2450c2a0
STIX ID: report--49509b9f-5200-51fa-9aab-30ac2450c2a0
Feed Name: Arctic Wolf
Arctic Wolf Labs documents the Caminho Loader, a Brazilian-origin Loader-as-a-Service active since at least March 2025 that uses LSB steganography to hide .NET loaders inside images hosted on legitimate services (e.g., archive.org). The multi-stage campaign begins with spear-phishing archives containing JavaScript/VBScript that fetch obfuscated PowerShell, which extracts a Base64-encoded .NET loader from images and injects final payloads (REMCOS RAT, XWorm, Katz Stealer) into calc.exe memory; persistence is achieved via scheduled tasks and numerous IOCs (file hashes, image URLs, pastebin links, C2 domains) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
