Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
186
Global rank
194
Month rank
191
Week rank
0
IOCs

Caminho Loader is a Brazilian-origin Loader-as-a-Service operation that uses steganography to conceal .NET payloads within image files hosted on legitimate platforms. Active since March 2025, it has delivered a variety of malware and infostealers to victims within multiple industries across South America, Africa, and Eastern Europe.

Loader
Type
Unknown
Origin
1 March, 2025
First seen
5 June, 2026
Last seen

How to analyze Caminho Loader with ANY.RUN

Type
Unknown
Origin
1 March, 2025
First seen
5 June, 2026
Last seen

IOCs

IP addresses
48.209.138.168
48.209.138.189
88.221.169.205
2.16.164.72
48.209.6.48
23.11.41.157
40.126.32.76
88.221.169.152
135.232.92.137
128.24.231.65
172.211.123.248
74.178.240.51
48.192.1.64
Hashes
336ac20032ed29eabad271d575712bf7423afeb0d83350bc58ce9335e44c5206
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
4dbfc417d053ba6867308671f1c61f4dcafc61f058d4044db532da6d3bde3615
bac3bf5f71fee8b42572d4bb8e41a4fc21afcce31e244e1669dc724b1c3fb6a4
958053784e0960bc5cc4be1a95dcbfb6128f5eb99719d32519eb878e0edae3b6
8945d4eb5a61303ab89a936479c0b21c6fee288f2301e4b91ef362118fe0528f
Domains
ocsp.digicert.com
slscr.update.microsoft.com
activation-v2.sls.microsoft.com
self.events.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
login.live.com
settings-win.data.microsoft.com
client.wns.windows.com
go.microsoft.com
crl.microsoft.com
nexusrules.officeapps.live.com
google.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
Last Seen at

Recent blog posts

post image
Hunt Malware & Phishing Threats with ANY....
watchers 856
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 5935
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 12616
comments 0

Caminho Loader: LSB Steganography Meets Loader-as-a-Service

Key Takeaways

  1. Caminho hides malicious .NET payloads inside innocent-looking images using Least Significant Bit steganography, making detection extremely challenging for traditional security controls.

  2. The malware loads and executes entirely in memory without writing files to disk, defeating file-based antivirus scanning and leaving minimal forensic artifacts.

  3. Caminho operates as a commercial service where multiple cybercriminal customers rent access to the delivery infrastructure while providing their own final payloads including REMCOS RAT, XWorm, and Katz Stealer.

  4. The operation exploits trusted services like archive.org for hosting steganographic images and Pastebin services for script staging, evading reputation-based security controls.

56 Active since March 2025 with confirmed victims in Brazil, South Africa, Ukraine, and Poland, demonstrating rapid geographic expansion beyond initial South American targeting.

  1. Use Threat Intelligence Lookup to determine if Caminho Loader is threatening your organization right now: see what countries and industries are being targeted, check potential IOCs:

threatName:"caminholoader" or threatName:"caminho".

Caminho Loader overview in TI Lookup Search for malware’s name to see active campaigns and fresh samples

  1. ANY.RUN's Interactive Sandbox provides critical visibility into Caminho's multi-stage execution, allowing security teams to observe steganographic extraction, memory-resident execution, and final payload delivery in real-time — capabilities that static analysis cannot provide.

View analysis

Caminho Loader malware analysis in Interactive Sandbox Caminho Loader malware analysis

What is Caminho Loader Malware?

Caminho Loader is a sophisticated Brazilian-origin Loader-as-a-Service (LaaS) malware, active since March 2025. It employs Least Significant Bit (LSB) steganography to conceal .NET payloads within innocuous image files, enabling fileless execution and delivery of various remote access trojans (RATs) and stealers like REMCOS, XWorm, and DCRAT.

Caminho, which means "path" in Portuguese, represents a significant evolution in malware delivery techniques. The PowerShell next extracts a concealed .NET Loader from the image using LSB steganography, loads it directly into memory, and invokes it with arguments specifying the final payload URL. What makes Caminho particularly dangerous is its fileless execution model that bypasses disk-based detection systems.

Analysis of 71 Caminho Loader samples reveals consistent architectural patterns despite varying obfuscation, with all samples containing Portuguese-language strings and the distinctive HackForums[.]gigajew namespace artifact. The loader implements extensive anti-analysis measures including virtual machine detection, sandbox identification, and debugging tool recognition, making it extremely difficult for security researchers to analyze.

The malware operates as a Loader-as-a-Service business model, meaning multiple cybercriminal customers can rent access to the delivery infrastructure while supplying their own final payloads. The standardized invocation interface accepts arbitrary payload URLs as arguments, allowing multiple customers to deploy different malware families using the same delivery infrastructure. This modular architecture explains why the same steganographic images appear across multiple campaigns delivering entirely different malware families.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Caminho Loader Victimology

Caminho primarily targets organizations in South America (especially Brazil), Africa (e.g., South Africa), and Eastern Europe (Ukraine, Poland). One notable campaign by the BlindEagle APT group (also known as APT-C-54) targeted a Colombian government agency under the Ministry of Commerce, Industry, and Tourism in September 2025. Victims span various industries, lured by business-themed phishing emails (invoices, quotations). Attacks are opportunistic rather than highly targeted at specific sectors, focusing on entities where users are likely to open attachments or links.

How Caminho Loader Infiltrates and Functions

The multi-stage infection chain begins with spear-phishing emails containing archived JavaScript (JS) or VBScript files using business-themed social engineering lures. The attackers craft convincing emails impersonating legitimate business communications, with compressed RAR or ZIP archives attached.

The archives use file names that are socially engineered to entice victims to open them. A fake invoice is one of the most common formats used for phishing, because the recipient's concern of missing a financial payment or being required to make one invokes a sense of urgency. Other common lures include quotation requests, business proposals, and shipping notifications.

When victims open these attachments and execute the JavaScript or VBScript file, the initial script contacts Pastebin-style services like paste.ee or pastefy.app to retrieve obfuscated PowerShell code. These legitimate pasting services provide free hosting and are difficult to block without disrupting legitimate business operations.

The PowerShell payload then downloads seemingly innocent images from trusted platforms like archive.org. Because these platforms enjoy high reputation scores and are used for legitimate purposes, security systems typically allow these downloads without raising alerts.

The PowerShell script then performs the steganographic extraction, loading the hidden Caminho Loader directly into memory. The loader subsequently reaches out to attacker-controlled infrastructure to download the final payload — REMCOS RAT, XWorm, Katz Stealer, or another malware family depending on the customer's choice.

Lateral movement and spreading depend on the final payload deployed. Remote access trojans like REMCOS and XWorm enable attackers to manually spread through networks by stealing credentials, mapping network resources, and deploying additional malware to other systems. However, Caminho Loader itself does not include self-propagation or worm-like spreading mechanisms.

Sandbox Analyses of Caminho Loader Samples

ANY.RUN’s Interactive Sandbox overcomes Caminho’s ant-detection and sandbox-evasion mechanics, exposing the full attack chain.

View a Caminho Loader sample analysis

Caminho Loader sandbox analysis Caminho Loader dissected in the Interactive Sandbox

The loader is a JavaScript script that uses several obfuscation techniques. Based on the tracer output, the following conclusion can be drawn:

The script initializes tools for file and network operations, determines its own current path, pauses for 5 seconds, and then silently launches a hidden PowerShell instance. After that, it prepares to download or process data from the internet.

Malicious script launching a PowerShell process Malicious script launching a PowerShell process

When the Base64 is decoded, it becomes clear that PowerShell downloads content from an image file hosted on archive.org, locates embedded Base64 data within it, converts that data into an executable program directly in memory, and then invokes a specific function with additional encrypted parameters and references to folders and files on the disk.

Loader retrieves its functionality from a web archive picture Loader retrieves its functionality from a web archive picture

In this sample analysis, the malicious payload has not been delivered. View another sandbox session to see how this might happen:

View another Caminho Loader analysis

As a result of the loader’s activity, we observe AsyncRAT injected into the AddInProcess32 process.

Caminho Loader delivers payload: AsyncRAT Caminho Loader delivers payload: AsyncRAT trojan

Gathering Threat Intelligence on Caminho Loader Malware

ANY.RUN's Threat Intelligence Lookup gives security teams instant access to a vast database of analyzed malware samples. Businesses can quickly search for Caminho-related hashes, domains, IPs, explore YARA/Sigma rules. This enables rapid blocking of indicators, enrichment of detection rules, and proactive threat hunting — helping organizations stop steganographic loaders and similar fileless threats before they cause damage.

Use TI Lookup to explore fresh Caminho samples analyzed in the Sandbox by a community of over 600K ANY.RUN’s users:

threatName:"caminholoader" or threatName:"caminho".

Caminho Loader sandbox analyses

Caminho Loader sandbox analyses

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Caminho Loader exemplifies modern malware evolution: blending steganography, fileless execution, and a service-based model to evade defenses. Originating from Brazil but impacting global victims, it underscores the need for layered security, user awareness, and advanced analysis tools to counter such stealthy threats.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More
TrustConnect screenshot
TrustConnect
trustconnect
TrustConnect is a MaaS platform that disguises a Remote Access Trojan (RAT) as a legitimate Remote Monitoring and Management (RMM) tool. The operators built an AI-generated business website, obtained a fraudulently acquired Extended Validation (EV) code-signing certificate, and created fake customer statistics and documentation to make TrustConnect appear to the world — and to security tools — as a legitimate software company.
Read More
Black Basta screenshot
Black Basta
blackbasta
Black Basta is a ransomware-as-a-service operated by Storm-1811. It emerged in 2022 and uses double extortion tactics, encrypting data and stealing it for ransom. The malware often gains access through spear-phishing and uses tools like QakBot and Cobalt Strike. It's known for exploiting system vulnerabilities and using advanced obfuscation techniques.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Rootkit screenshot
Rootkit
rootkit bootkit
A rootkit is a type of malicious software designed to provide unauthorized administrative-level access to a computer or network while concealing its presence. Rootkits are tools used by cybercriminals to hide their activities, including keyloggers, spyware, and other malware, often enabling long-term system exploitation.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More