Netskope Threat Labs

CatB

ATP Sandbox Adv. HeuristicsAV

CatB is a ransomware family documented in late 2022 that steals data alongside file encryption. It abuses DLL side-loading and hijacking of the MSDTC service to execute and evade detection, and researchers have connected it to the Chamelgang cyberespionage cluster, which is unusual for a ransomware operation.

First seen
February 2023
Last seen
October 2026
Alert Name
Dropped:Trojan.Ransom.CatB.A
Trojan.Ransom.CatB.A
Win64.Ransomware.CatB
Win64.Trojan.CatB