ATT&CKReferencesSymantec Catchamas April 2018

Symantec Catchamas April 2018

Balanza, M. (2018, April 02). Infostealer.Catchamas. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareCatchamas

Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on.

T1016
System Network Configuration Discovery
MalwareCatchamas

Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine.

T1036.004
Masquerade Task or Service
MalwareCatchamas

Catchamas adds a new service named NetAdapter in an apparent attempt to masquerade as a legitimate service.

T1056.001
Keylogging
MalwareCatchamas

Catchamas collects keystrokes from the victim’s machine.

T1074.001
Local Data Staging
MalwareCatchamas

Catchamas stores the gathered data from the machine in .db files and .bmp files under four separate locations.

T1112
Modify Registry
MalwareCatchamas

Catchamas creates three Registry keys to establish persistence by adding a Windows Service.

T1113
Screen Capture
MalwareCatchamas

Catchamas captures screenshots based on specific keywords in the window’s title.

T1115
Clipboard Data
MalwareCatchamas

Catchamas steals data stored in the clipboard.

T1543.003
Windows Service
MalwareCatchamas

Catchamas adds a new service named NetAdapter to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.