Kothamine malware uses Tailscale's tailcat to evade network detection
An undocumented remote-access Trojan named Kothamine Agent has been discovered with support for over 30 commands, enabling attackers to control infected Windows systems through command execution, file manipulation, and capability extension. Some variants include browser data theft and camera/microphone recording functionality. The malware has been distributed through malicious npm packages and utilizes tailcat, an open-source Tailscale tool, to establish encrypted command-and-control communications that evade conventional network inspection and blocking. Earlier versions employed Tailscale VPN before transitioning to tailcat. Active since July based on VirusTotal and GitHub evidence, Kothamine features a plugin system for loading additional DLLs, UAC bypass capabilities in certain builds, and employs AES-GCM encryption for C2 communications. The malware achieves persistence through scheduled tasks and adds Windows Defender exclusions during installation.
AI Analysis
Technical Summary
Kothamine Agent is an undocumented Windows remote-access Trojan that enables attackers to control infected systems through a wide range of commands. It has been distributed through malicious npm packages and uses tailcat, an open-source Tailscale tool, to create encrypted C2 channels that evade conventional network inspection and blocking. Earlier versions used Tailscale VPN before switching to tailcat. The malware supports over 30 commands, including file operations, command execution, and extensions via plugins. Some variants include browser data theft and camera/microphone recording. Persistence is maintained via scheduled tasks and Windows Defender exclusions. Communication is encrypted using AES-GCM. The malware also includes UAC bypass capabilities in certain builds. It has been active since at least July 2026, as evidenced by VirusTotal and GitHub data.
Potential Impact
Kothamine enables attackers to remotely control infected Windows systems with extensive capabilities, including executing commands, manipulating files, stealing browser data, and recording audio/video. Its use of encrypted C2 communications via tailcat allows it to evade network detection and blocking. The malware's persistence mechanisms and Windows Defender exclusions increase its resilience on infected hosts. The presence of UAC bypass in some variants further enhances its ability to operate stealthily and with elevated privileges.
Mitigation Recommendations
No official patch or remediation is indicated. Since this is malware distributed via malicious npm packages, mitigation should focus on preventing installation of untrusted packages and monitoring for suspicious scheduled tasks and Windows Defender exclusions. Network defenders should be aware that Kothamine uses tailcat for encrypted C2, which may evade traditional network inspection tools. Endpoint detection and response solutions should look for indicators such as the known hashes and domains associated with Kothamine. Regularly updating security software and applying principle of least privilege can help reduce impact.
Indicators of Compromise
- domain: third-party.com
- hash: ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0
- hash: 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c
Kothamine malware uses Tailscale's tailcat to evade network detection
Description
An undocumented remote-access Trojan named Kothamine Agent has been discovered with support for over 30 commands, enabling attackers to control infected Windows systems through command execution, file manipulation, and capability extension. Some variants include browser data theft and camera/microphone recording functionality. The malware has been distributed through malicious npm packages and utilizes tailcat, an open-source Tailscale tool, to establish encrypted command-and-control communications that evade conventional network inspection and blocking. Earlier versions employed Tailscale VPN before transitioning to tailcat. Active since July based on VirusTotal and GitHub evidence, Kothamine features a plugin system for loading additional DLLs, UAC bypass capabilities in certain builds, and employs AES-GCM encryption for C2 communications. The malware achieves persistence through scheduled tasks and adds Windows Defender exclusions during installation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kothamine Agent is an undocumented Windows remote-access Trojan that enables attackers to control infected systems through a wide range of commands. It has been distributed through malicious npm packages and uses tailcat, an open-source Tailscale tool, to create encrypted C2 channels that evade conventional network inspection and blocking. Earlier versions used Tailscale VPN before switching to tailcat. The malware supports over 30 commands, including file operations, command execution, and extensions via plugins. Some variants include browser data theft and camera/microphone recording. Persistence is maintained via scheduled tasks and Windows Defender exclusions. Communication is encrypted using AES-GCM. The malware also includes UAC bypass capabilities in certain builds. It has been active since at least July 2026, as evidenced by VirusTotal and GitHub data.
Potential Impact
Kothamine enables attackers to remotely control infected Windows systems with extensive capabilities, including executing commands, manipulating files, stealing browser data, and recording audio/video. Its use of encrypted C2 communications via tailcat allows it to evade network detection and blocking. The malware's persistence mechanisms and Windows Defender exclusions increase its resilience on infected hosts. The presence of UAC bypass in some variants further enhances its ability to operate stealthily and with elevated privileges.
Defensive Guidance
No official patch or remediation is indicated. Since this is malware distributed via malicious npm packages, mitigation should focus on preventing installation of untrusted packages and monitoring for suspicious scheduled tasks and Windows Defender exclusions. Network defenders should be aware that Kothamine uses tailcat for encrypted C2, which may evade traditional network inspection tools. Endpoint detection and response solutions should look for indicators such as the known hashes and domains associated with Kothamine. Regularly updating security software and applying principle of least privilege can help reduce impact.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection"]
- Pulse Id
- 6ab7c5997e2556d7c00c86e6
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainthird-party.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0 | — | |
hash74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c | — |
Threat ID: 6aba7398f7a7c54106c4628d
Added to database: 09/28/2026, 14:03:04 UTC
Last enriched: 09/28/2026, 14:18:22 UTC
Last updated: 09/29/2026, 01:55:31 UTC
Views: 92
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.