CatB, also known as CatB99 or Baxtoy, is a Windows ransomware family first observed in late 2022. It is associated with ChamelGang, also known as CamoFei, through overlaps in code, staging mechanisms, and malware artifacts. CatB has been linked to ransomware attacks against government and healthcare institutions, including the Presidency of Brazil and the All India Institute of Medical Sciences.
CatB uses a DLL-based loader that checks processor count, physical memory, and disk capacity to detect virtualized or analysis environments. After these checks pass, the loader deploys the ransomware payload and abuses DLL loading in the Microsoft Distributed Transaction Coordinator (MSDTC) service to execute it within a trusted Windows service process. The loader configures the service for automatic startup and execution under LocalSystem, supporting persistence and elevated execution. The ransomware payload repeats the environment checks before encrypting files. Its initial delivery vector is not established.
CatB searches multiple local drives and applies file-extension inclusion and exclusion rules. It fully encrypts targeted files smaller than approximately 52 MB, while larger files and eligible files outside its primary extension list receive partial encryption of their first 20,480 bytes. Unlike many ransomware families, it leaves file extensions unchanged and prepends a ransom note to each encrypted file rather than creating separate notes. The note demands payment and threatens permanent data loss. CatB also attempts to collect sensitive browser and Windows Mail data, including credentials, browser session keys, browsing history, autofill information, and profile data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its ransomware payload, known as CatB, had been signed with the same coolschool certificate.
Its ransomware payload, known as CatB, had been signed with the same coolschool certificate.
"Its ransomware payload, known as CatB, had been signed with the same coolschool certificate."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The CatB ransomware sample discussed in this Spotlight uses a DLL Side-Loading vulnerability in a trusted Windows service called MSDTC.
The malware then abuses the MSDTC service, manipulating the permissions and startup parameters. As a result, the system will inject the malicious oci.dll into the service’s executable (msdtc.exe) when the MSDTC service is restarted. | Upon execution, CatB payloads rely on DLL search order hijacking to drop and load the malicious payload. The dropper (versions.dll) drops the payload (oci.dll) into the System32 directory.
First, the dropper is distributed in the form of a UPX-packed DLL (versions.dll). This dropper deposits the second DLL payload (oci.dll) onto the target host.
The ChamelGang group repeatedly deployed ransomware and encryptors “for the purposes of financial gain, disruption, distraction, misattribution, or removal of evidence” ... The specific use of ransomware also allows APT groups to destroy evidence of their espionage efforts and force organizations to focus on data restoration instead of investigating how hackers gained initial entry.
As a result, the system will inject the malicious oci.dll into the service’s executable (msdtc.exe) when the MSDTC service is restarted.
Before the ransomware is executed, its loader component performs basic evasion checks to ensure the sample is not running in an analysis environment, such as a sandbox.
The first one checks the number of CPU cores... The second performed anti-VM technique checks for the amount of main memory... For the third and final check, the sample extracts the size of the hard drive...
The CatB ransomware sample discussed in this Spotlight uses a DLL Side-Loading vulnerability in a trusted Windows service called MSDTC.
The malware then abuses the MSDTC service, manipulating the permissions and startup parameters. As a result, the system will inject the malicious oci.dll into the service’s executable (msdtc.exe) when the MSDTC service is restarted. | Upon execution, CatB payloads rely on DLL search order hijacking to drop and load the malicious payload. The dropper (versions.dll) drops the payload (oci.dll) into the System32 directory.
CatB performs three primary checks in an attempt to determine if the payload is being executed within a virtual environment. These are direct checks for type and size of physical RAM, type and size of physical hard disks, and checking for odd or anomalous combinations of processors and cores.
Once CatB passes all the checks for the second time, the ransomware tries to find interesting files to encrypt... searching for files across multiple drives.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware payload attributed by TeamT5 to the China-linked group CamoFei; notable for being signed with the stolen 'coolschool' certificate also seen in later Warlock-adjacent tooling.
Ransomware associated with CamoFe i, also identified as ChamelGang. Its use of the same stolen signing certificate observed in Warlock-related defense-evasion tools supports a possible historical connection, but does not establish that CatB and Warlock are the same family.
Ransomware associated with ChamelGang and used in attacks against the Presidency of Brazil and India’s AIIMS.
Ransomware that the content says exploits DLL hijacking vulnerabilities for improved concealment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.