216.73.217.22

Brazilian Caminho Loader Employs LSB Steganography and Fileless Execution to Deliver Multiple Malware Families Across South America, Africa, and Eastern Europe

· Published 22/10/2025 04:00 · Modified 22/10/2025 08:37

Export JSON

Essential information

Published
22/10/2025 04:00
Modified
22/10/2025 08:37
Tags
2025-10-22 africa brazil caminho loader eastern europe fileless execution katz stealer loader-as-a-service remcos rat south america steganography xworm
Related entities
15 techniques (mitre), 4 malware, 4 others

Description

A new malware loader called Caminho, originating from , has been identified using to hide .NET payloads in image files hosted on legitimate platforms. Active since March 2025, the campaign has evolved significantly, delivering various malware types across , , and . The multi-stage infection chain begins with phishing emails containing malicious scripts, leading to the download of steganographic images. The extracts and executes payloads in memory, establishing persistence through scheduled tasks. Analysis reveals consistent patterns and Portuguese language artifacts, indicating a model. The operation targets multiple industries opportunistically, using bulletproof hosting for command and control.

External references