Malware.View on attack.mitre.org
Catchamas is a Windows Trojan that steals information from compromised systems.
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on. |
| T1016 System Network Configuration Discovery |
Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine. |
| T1036.004 Masquerade Task or Service |
Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service. |
| T1056.001 Keylogging |
Catchamas collects keystrokes from the victim’s machine. |
| T1074.001 Local Data Staging |
Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations. |
| T1112 Modify Registry |
Catchamas creates three Registry keys to establish persistence by adding a Windows Service. |
| T1113 Screen Capture |
Catchamas captures screenshots based on specific keywords in the window’s title. |
| T1115 Clipboard Data |
Catchamas steals data stored in the clipboard. |
| T1543.003 Windows Service |
Catchamas adds a new service named NetAdapter to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.