Caminho Loader-as-a-Service Uses Steganography for Malware Delivery

Cybersecurity researchers have identified a new threat called Caminho, a Loader-as-a-Service (LaaS) that hides .NET payloads in images using Least Significant Bit (LSB) steganography. Active since March 2025, this operation targets businesses through spear-phishing emails with social engineering bait. The attack involves JavaScript or VBScript files that fetch obfuscated PowerShell code, which then extracts the malicious payload from images hosted on trusted sites. This fileless approach, combined with anti-analysis tricks, makes Caminho hard to detect. The loader injects final malware into benign processes and sets up persistence through scheduled tasks.

Latest mentioned: 10-23
Earliest mentioned: 10-22