Skip to main content

Kothamine malware uses Tailscale's tailcat to evade network detection

0
Medium
Published: 09/26/2026 (09/26/2026, 13:16:09 UTC)
Source: AlienVault OTX General

Description

An undocumented remote-access Trojan named Kothamine Agent has been discovered with support for over 30 commands, enabling attackers to control infected Windows systems through command execution, file manipulation, and capability extension. Some variants include browser data theft and camera/microphone recording functionality. The malware has been distributed through malicious npm packages and utilizes tailcat, an open-source Tailscale tool, to establish encrypted command-and-control communications that evade conventional network inspection and blocking. Earlier versions employed Tailscale VPN before transitioning to tailcat. Active since July based on VirusTotal and GitHub evidence, Kothamine features a plugin system for loading additional DLLs, UAC bypass capabilities in certain builds, and employs AES-GCM encryption for C2 communications. The malware achieves persistence through scheduled tasks and adds Windows Defender exclusions during installation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 14:18:22 UTC

Technical Analysis

Kothamine Agent is an undocumented Windows remote-access Trojan that enables attackers to control infected systems through a wide range of commands. It has been distributed through malicious npm packages and uses tailcat, an open-source Tailscale tool, to create encrypted C2 channels that evade conventional network inspection and blocking. Earlier versions used Tailscale VPN before switching to tailcat. The malware supports over 30 commands, including file operations, command execution, and extensions via plugins. Some variants include browser data theft and camera/microphone recording. Persistence is maintained via scheduled tasks and Windows Defender exclusions. Communication is encrypted using AES-GCM. The malware also includes UAC bypass capabilities in certain builds. It has been active since at least July 2026, as evidenced by VirusTotal and GitHub data.

Potential Impact

Kothamine enables attackers to remotely control infected Windows systems with extensive capabilities, including executing commands, manipulating files, stealing browser data, and recording audio/video. Its use of encrypted C2 communications via tailcat allows it to evade network detection and blocking. The malware's persistence mechanisms and Windows Defender exclusions increase its resilience on infected hosts. The presence of UAC bypass in some variants further enhances its ability to operate stealthily and with elevated privileges.

Defensive Guidance

No official patch or remediation is indicated. Since this is malware distributed via malicious npm packages, mitigation should focus on preventing installation of untrusted packages and monitoring for suspicious scheduled tasks and Windows Defender exclusions. Network defenders should be aware that Kothamine uses tailcat for encrypted C2, which may evade traditional network inspection tools. Endpoint detection and response solutions should look for indicators such as the known hashes and domains associated with Kothamine. Regularly updating security software and applying principle of least privilege can help reduce impact.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection"]
Pulse Id
6ab7c5997e2556d7c00c86e6

Indicators of Compromise

Domain

ValueDescriptionCopy
domainthird-party.com
—

Hash

ValueDescriptionCopy
hashec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0
—
hash74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c
—

Threat ID: 6aba7398f7a7c54106c4628d

Added to database: 09/28/2026, 14:03:04 UTC

Last enriched: 09/28/2026, 14:18:22 UTC

Last updated: 09/29/2026, 01:55:31 UTC

Views: 92

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses