Caminho

S9016

Malware.View on attack.mitre.org

About this malware

Caminho is a downloader that has been used by threat actors since at least 2025 to deliver various strains of malware such as XWorm.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.001
Binary Padding

Caminho can use junk code for obfuscation.

T1027.013
Encrypted/Encoded File

Caminho can use code flattening for payload obfuscation.

T1055.012
Process Hollowing

Caminho has launched and hollowed out MSBuild.exe to host malicious code.

T1105
Ingress Tool Transfer

Caminho has the ability to download files onto compromised hosts.

T1106
Native API

Caminho can use `System.Net.WebClient.downloadString()` for file download.

T1140
Deobfuscate/Decode Files or Information

Caminho can deobfuscate downloaded files prior to execution.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler BlindEagle DEC 2025 Open source
    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.