Catchamas is a custom Windows trojan associated with the threat cluster tracked as BRONZE THORNWELL. It is designed for post-compromise surveillance and collection on infected hosts. Reported functionality includes selective screen capture based on application window titles or keywords, collection of keystrokes, theft of clipboard contents, and gathering of local network configuration details such as MAC address, IP address, and network adapter information. Catchamas also enumerates application window titles to decide which windows should be captured, indicating targeted monitoring of user activity rather than indiscriminate collection alone. For persistence, it establishes a Windows service and creates related Registry entries so the malware can survive reboots. Collected information is staged locally in database and bitmap files before onward handling by the operator. The malware has been described alongside other custom tooling used with living-off-the-land techniques during intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE THORNWELL leverage custom trojans Catchamas and Rikamanu; and heavily use living of the land techniques post-compromise.
BRONZE THORNWELL leverage custom trojans Catchamas and Rikamanu; and heavily use living of the land techniques post-compromise.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
Catchamas creates three Registry keys to establish persistence by adding a Windows Service ... TEARDROP modified the Registry to create a Windows service for itself ... NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gathers MAC address, IP address, and network adapter information from victims.
Backdoor that gathers MAC address, IP address, and network adapter information.
Spyware that conditionally captures screenshots based on window-title keywords.
Malware that creates Registry keys to establish persistence via a Windows service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.