Malware.View on attack.mitre.org
Caminho is a downloader that has been used by threat actors since at least 2025 to deliver various strains of malware such as XWorm.
| Technique | Procedure example |
|---|---|
| T1027.001 Binary Padding |
Caminho can use junk code for obfuscation. |
| T1027.013 Encrypted/Encoded File |
Caminho can use code flattening for payload obfuscation. |
| T1055.012 Process Hollowing |
Caminho has launched and hollowed out MSBuild.exe to host malicious code. |
| T1105 Ingress Tool Transfer |
Caminho has the ability to download files onto compromised hosts. |
| T1106 Native API |
Caminho can use `System.Net.WebClient.downloadString()` for file download. |
| T1140 Deobfuscate/Decode Files or Information |
Caminho can deobfuscate downloaded files prior to execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.