Catchamas

S0261

Malware.View on attack.mitre.org

About this malware

Catchamas is a Windows Trojan that steals information from compromised systems.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1010
Application Window Discovery

Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on.

T1016
System Network Configuration Discovery

Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine.

T1036.004
Masquerade Task or Service

Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service.

T1056.001
Keylogging

Catchamas collects keystrokes from the victim’s machine.

T1074.001
Local Data Staging

Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations.

T1112
Modify Registry

Catchamas creates three Registry keys to establish persistence by adding a Windows Service.

T1113
Screen Capture

Catchamas captures screenshots based on specific keywords in the window’s title.

T1115
Clipboard Data

Catchamas steals data stored in the clipboard.

T1543.003
Windows Service

Catchamas adds a new service named NetAdapter to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Catchamas April 2018 Open source
    Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.