Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control

Summary
Researchers detail Kothamine, a Windows RAT linked to malicious npm packages. Recent versions use Tailscale’s tailcat for encrypted command communications; some builds can steal browser data and capture audio or video.
Key points
- Kothamine is a Windows RAT linked to malicious npm packages, including dotnet-runtime-base; it supports more than 30 commands for system control, file operations, shell execution, and loading DLL plugins.
- Recent versions use tailcat to relay encrypted commands, while earlier variants used Tailscale VPN. The approach avoids relying on a conventional C2 domain.
- The injector can add Windows Defender exclusions, copy itself and its DLL into the user’s roaming profile, inject the DLL into explorer.exe, and establish logon persistence with a scheduled task.
- Some builds support stealing browser data, cookies, gaming-related files, and clipboard contents, as well as taking screenshots and recording from the camera and microphone.
- Certain variants use fodhelper.exe for UAC bypass; newer versions also obfuscate strings. The researchers say samples and GitHub activity indicate Kothamine dates back to at least July.
- The article provides sample hashes and filenames, including MicrosoftEdgeUpdateCore.exe and MicrosoftEdgeUpdateCore.dll, to support identification.
Article Details
- Attack Vectors
- Kothamine Agent was linked to malicious npm packages, including dotnet-runtime-base, which downloaded a Kothamine executable from a GitHub repository.
- Kothamine Injector injected the agent DLL into a running process, typically explorer.exe.
- Recent builds used tailcat to forward encrypted command traffic through a local port to an operator node; earlier builds used Tailscale VPN.
- The agent could receive base64-encoded DLLs from an operator, write and load them, and execute their exported functionality.
- Some builds used fodhelper.exe to bypass User Account Control and run a PowerShell script.
- Defensive Notes
- Before installing an unfamiliar npm package, check its name, repository, maintainer, dependencies, releases, reviews, and reports of malicious activity.
- The analyzed injector and agent added Microsoft Defender exclusions for their files and process names.
- Recent tailcat-based builds did not require a conventional command-and-control domain to block.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c | SHA-256 of the Kothamine Agent analyzed in the article. |
| SHA256 | ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0 | SHA-256 of the Kothamine Injector analyzed in the article. |
| URL | hxxps[:]//github[.]com/cphc811-ui/ | GitHub repository identified as a source of executables and DLLs associated with the malicious package and Kothamine. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationRecent Kothamine builds concealed strings by decrypting them inline or with per-string XOR keys.T1053.005 · Scheduled TaskThe dropped up.ps1 script registered a scheduled task to launch Kothamine Injector at user logon.T1055 · Process InjectionKothamine Injector injected the agent DLL into a running process, typically explorer.exe, using remote-process memory and thread APIs.T1090 · ProxyKothamine used tailcat to forward connections from a local TCP port to port 4444 on an operator node.T1105 · Ingress Tool TransferKothamine builds downloaded Tailscale components, while the agent could receive, write, and load additional DLLs sent by an operator.T1113 · Screen CaptureA Kothamine build hosted on GitHub included a screenshot command.T1115 · Clipboard DataSome Kothamine builds could access clipboard contents.T1123 · Audio CaptureSome Kothamine builds could record through a microphone.T1125 · Video CaptureSome Kothamine builds could record through a camera.T1539 · Steal Web Session CookieStealer-capable Kothamine builds included commands to collect browser cookies.T1548.002 · Bypass User Account ControlSome Kothamine builds used fodhelper.exe to bypass User Account Control and run elevated.ps1.T1562.001 · Disable or Modify ToolsThe injector and agent used PowerShell to add their files and process names to Microsoft Defender exclusions.T1573.001 · Symmetric CryptographyKothamine encrypted and decrypted messages exchanged with its command-and-control endpoint using AES-GCM.
Malware
Vendors
Microsoft[T1562.001 ] Impair Defenses: Disable or Modify Tools – It weakens Microsoft Defender by excluding its files and process names from scanning [‘Adds Windows Defender exclusions using PowerShell’]TailscaleRecent variants use tailcat and earlier ones used Tailscale VPN, giving operators encrypted command access while avoiding a conventional C2 domain.
Products
Microsoft Defender[T1562.001 ] Impair Defenses: Disable or Modify Tools – It weakens Microsoft Defender by excluding its files and process names from scanning [‘Adds Windows Defender exclusions using PowerShell’]npmResearchers uncovered Kothamine Agent, an undocumented RAT linked to malicious npm packages that can control Windows systems, steal browser data, and capture audio/video on some builds.Tailscale VPNRecent variants use tailcat and earlier ones used Tailscale VPN, giving operators encrypted command access while avoiding a conventional C2 domain.WindowsResearchers uncovered Kothamine Agent, an undocumented RAT linked to malicious npm packages that can control Windows systems, steal browser data, and capture audio/video on some builds.