Saturday, August 15, 2026
LIVE
Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///Ugandan villages still contest land titles as oil development advances///Nigerian Troops Repel Bandit Attack on Kebbi Workers///NLC Queries Lagos Chairman Over Ties to Pro-Tinubu Group///Côte d’Ivoire Names New Leader for Blé Goudé’s COJEP Party///United States Highlights Civilian Deaths in Nigeria Terror Fight///Zimbabwe Pledges New Ferry and Road Repair After Lake Kariba Disaster///Ebola death toll reaches two thousand in Democratic Republic of the Congo///Forced Conscription Reports Emerge Across Ethiopia Oromia Region///Ebola outbreak reaches displacement camps in eastern Democratic Republic of the Congo///Hacking Group Claims Data Theft from Shell and Other Global Firms///Turkey warns of radical measures if Israel rejects Gaza peace deal terms///Nigerian President Urged to Engage Niger Delta Leader for Reelection Campaign///
Subscribe
Africa
Independent · Digital
The African Herald
PoliticsAI-assisted

Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files

The Caminho Loader represents a new Loader-as-a-Service model that uses steganography, fileless execution, and cloud exploitation to discreetly distribute malware across various regions.

The Caminho Loader represents a new Loader-as-a-Service model that uses steganography, fileless execution, and cloud exploitation to discreetly distribute malware across various regions.

Initially identified in March 2025 and believed to originate from Brazil, this service conceals .NET payloads within innocuous-looking image files hosted on trusted platforms.

Upon activation, it deploys a variety of remote access trojans and infostealers, such as REMCOS RAT, XWorm, Katz Stealer, and AsyncRAT, to compromise the targeted systems.

The operation targets organizations in South America, Africa, and Eastern Europe, with confirmed incidents in Brazil, South Africa, Ukraine, and Poland.

Attackers utilize convincing phishing emails with business-related themes like invoices and shipping notices to entice users into opening attached archive files.

These RAR or ZIP archives contain obfuscated JavaScript or VBScript files that act as the initial execution point, silently initiating the multi-stage infection chain when opened by the victim.

ANY.RUN analysts identified Caminho Loader while investigating suspicious submissions in their interactive sandbox, noting consistent use of steganography, in-memory execution, and a flexible delivery model.

The research indicates that all analyzed samples include Portuguese strings and the distinctive "HackForums.gigajew" namespace, indicating a connection to Brazil.

The Caminho Loader represents a new Loader-as-a-Service model that uses steganography, fileless execution, and cloud exploitation to discreetly distribute malware across various regions.
Kwame Osei · The African Herald

The loader's impact is significant because it does not rely on a single malware family. Instead, criminal customers rent the delivery infrastructure and incorporate their own .NET payloads through standardized parameters.

This modular approach allows multiple campaigns to use the same steganographic images and scripts while delivering entirely different trojans to end targets.

For defenders, this means that one loader infrastructure can support credential theft , espionage, or remote access, depending on the campaign's operator.

How Caminho Loader’s Steganographic Infection Chain Works

The infection chain behind Caminho Loader utilizes legitimate services at almost every step, complicating filtration without disrupting normal business traffic.

After the victim executes the malicious JavaScript or VBScript from a phishing archive, the script connects to services like paste.ee or pastefy.app to download heavily obfuscated PowerShell code.

This PowerShell stage then accesses reputable platforms like archive.org to retrieve image files that appear benign to both users and security tools.

Advertisement

Within these images, Caminho encodes Base64 .NET loader code using Least Significant Bit (LSB) steganography, embedding data into the least visible parts of pixel values without altering the image's appearance.

The PowerShell script scans the downloaded image, extracts the hidden data, reconstructs the .NET assembly directly in memory, and executes it with arguments that include the final payload URL.

Because the loader does not write the executable to disk, traditional file-based antivirus tools often miss detecting the malicious component.

Once operational in memory, the Caminho Loader connects to attacker-controlled infrastructure to download and execute the chosen payload, such as REMCOS or AsyncRAT , which then facilitates lateral movement, credential theft, and sustained access.

The AsyncRAT Injection case documented an instance where the loader injected AsyncRAT into the AddInProcess32 process, blending into normal system activity.

ANY.RUN's sandbox analysis provides defenders with a comprehensive view of a threat designed to leave minimal forensic traces.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories