Caminho is a Windows .NET malware loader operated as a Loader-as-a-Service offering and assessed to originate from Brazilian Portuguese-speaking operators. It has been observed in multi-stage intrusion chains that use steganography to conceal the loader inside image files, including Least Significant Bit techniques, and then execute payloads directly in memory. Caminho is designed to retrieve a downstream malware URL at runtime, decode it, and deliver arbitrary customer payloads, which has included REMCOS RAT, XWorm, Katz Stealer, and DCRat. This modularity, combined with architecture checks and varying obfuscation, is consistent with a service used by multiple affiliates or customers rather than a single bespoke campaign.
The loader is commonly delivered through spearphishing campaigns using business-themed lures and archive attachments containing obfuscated script stages, and it has also appeared in phishing chains using malicious documents or SVG-based redirection. Subsequent stages typically invoke PowerShell to download a steganographic image from legitimate hosting services, extract the embedded .NET assembly, and load it without writing the executable payload to disk. Caminho then launches or hollows legitimate Windows processes, including observed use of MSBuild.exe and other benign binaries, to host malicious code and evade detection.
Caminho includes anti-analysis and defense-evasion features such as virtual machine, sandbox, debugger, and security-tool detection. It also validates payload architecture before execution and supports in-memory execution and process injection or hollowing for downstream malware. Persistence has been established in observed campaigns through scheduled tasks that repeatedly relaunch the infection chain. Campaigns using Caminho have targeted government and public-sector entities, including Colombian government organizations, and have also affected victims across multiple regions beyond South America. Caminho has been linked to phishing operations associated with BlindEagle and to broader commodity malware delivery activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes adversaries using Base64, XOR, RC4, AES, hexadecimal encoding, string encryption, code flattening, custom crypters, and other obfuscation methods to hide payloads, strings, configuration data, URLs, and scripts.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity loader used to distribute a variety of malware, leveraging steganography and multiple infection vectors.
Downloader malware used to fetch and execute additional payloads, specifically DCRAT, as part of a multi-stage attack chain. Caminho is notable for its use of Portuguese language artifacts and is delivered via a fileless, in-memory PowerShell execution.
Loader malware used to deliver DCRat in phishing campaigns targeting Colombian government agencies.
Downloader malware that retrieves additional payloads from remote sources, in this case from Discord CDN, and decodes them in memory for further execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.