Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareCatchamas | Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on. |
| T1016 System Network Configuration Discovery |
MalwareCatchamas | Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine. |
| T1036.004 Masquerade Task or Service |
MalwareCatchamas | Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service. |
| T1056.001 Keylogging |
MalwareCatchamas | Catchamas collects keystrokes from the victim’s machine. |
| T1074.001 Local Data Staging |
MalwareCatchamas | Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations. |
| T1112 Modify Registry |
MalwareCatchamas | Catchamas creates three Registry keys to establish persistence by adding a Windows Service. |
| T1113 Screen Capture |
MalwareCatchamas | Catchamas captures screenshots based on specific keywords in the window’s title. |
| T1115 Clipboard Data |
MalwareCatchamas | Catchamas steals data stored in the clipboard. |
| T1543.003 Windows Service |
MalwareCatchamas | Catchamas adds a new service named NetAdapter to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.