Threats Tagged 'kothamine agent'
View all threats tagged with 'kothamine agent'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'kothamine agent'
Click on any threat for detailed analysis and mitigation recommendations
An undocumented remote-access Trojan named Kothamine Agent has been discovered with support for over 30 commands, enabling attackers to control infected Windows systems through command execution, file manipulation, and capability extension. Some variants include browser data theft and camera/microphone recording functionality. The malware has been distributed through malicious npm packages and utilizes tailcat, an open-source Tailscale tool, to establish encrypted command-and-control communications that evade conventional network inspection and blocking. Earlier versions employed Tailscale VPN before transitioning to tailcat. Active since July based on VirusTotal and GitHub evidence, Kothamine features a plugin system for loading additional DLLs, UAC bypass capabilities in certain builds, and employs AES-GCM encryption for C2 communications. The malware achieves persistence through scheduled tasks and adds Windows Defender exclusions during installation. Join the discussion | AlienVault OTX General | 09/26/2026, 13:16:09 UTC Added: 09/28/2026, 14:03:04 UTC |
Showing 1 to 1 of 1 result