Kothamine RAT Uses Tailscale’s Tailcat for Encrypted Command-and-Control

· Original article ↗

Summary

Researchers detail Kothamine, a Windows RAT linked to malicious npm packages. Recent versions use Tailscale’s tailcat for encrypted command communications; some builds can steal browser data and capture audio or video.

Key points

  • Kothamine is a Windows RAT linked to malicious npm packages, including dotnet-runtime-base; it supports more than 30 commands for system control, file operations, shell execution, and loading DLL plugins.
  • Recent versions use tailcat to relay encrypted commands, while earlier variants used Tailscale VPN. The approach avoids relying on a conventional C2 domain.
  • The injector can add Windows Defender exclusions, copy itself and its DLL into the user’s roaming profile, inject the DLL into explorer.exe, and establish logon persistence with a scheduled task.
  • Some builds support stealing browser data, cookies, gaming-related files, and clipboard contents, as well as taking screenshots and recording from the camera and microphone.
  • Certain variants use fodhelper.exe for UAC bypass; newer versions also obfuscate strings. The researchers say samples and GitHub activity indicate Kothamine dates back to at least July.
  • The article provides sample hashes and filenames, including MicrosoftEdgeUpdateCore.exe and MicrosoftEdgeUpdateCore.dll, to support identification.

Article Details

Attack Vectors
  • Kothamine Agent was linked to malicious npm packages, including dotnet-runtime-base, which downloaded a Kothamine executable from a GitHub repository.
  • Kothamine Injector injected the agent DLL into a running process, typically explorer.exe.
  • Recent builds used tailcat to forward encrypted command traffic through a local port to an operator node; earlier builds used Tailscale VPN.
  • The agent could receive base64-encoded DLLs from an operator, write and load them, and execute their exported functionality.
  • Some builds used fodhelper.exe to bypass User Account Control and run a PowerShell script.
Defensive Notes
  • Before installing an unfamiliar npm package, check its name, repository, maintainer, dependencies, releases, reviews, and reports of malicious activity.
  • The analyzed injector and agent added Microsoft Defender exclusions for their files and process names.
  • Recent tailcat-based builds did not require a conventional command-and-control domain to block.

Indicators of compromise

TypeIndicatorContext
SHA25674eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70cSHA-256 of the Kothamine Agent analyzed in the article.
SHA256ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0SHA-256 of the Kothamine Injector analyzed in the article.
URLhxxps[:]//github[.]com/cphc811-ui/GitHub repository identified as a source of executables and DLLs associated with the malicious package and Kothamine.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationRecent Kothamine builds concealed strings by decrypting them inline or with per-string XOR keys.T1053.005 · Scheduled TaskThe dropped up.ps1 script registered a scheduled task to launch Kothamine Injector at user logon.T1055 · Process InjectionKothamine Injector injected the agent DLL into a running process, typically explorer.exe, using remote-process memory and thread APIs.T1090 · ProxyKothamine used tailcat to forward connections from a local TCP port to port 4444 on an operator node.T1105 · Ingress Tool TransferKothamine builds downloaded Tailscale components, while the agent could receive, write, and load additional DLLs sent by an operator.T1113 · Screen CaptureA Kothamine build hosted on GitHub included a screenshot command.T1115 · Clipboard DataSome Kothamine builds could access clipboard contents.T1123 · Audio CaptureSome Kothamine builds could record through a microphone.T1125 · Video CaptureSome Kothamine builds could record through a camera.T1539 · Steal Web Session CookieStealer-capable Kothamine builds included commands to collect browser cookies.T1548.002 · Bypass User Account ControlSome Kothamine builds used fodhelper.exe to bypass User Account Control and run elevated.ps1.T1562.001 · Disable or Modify ToolsThe injector and agent used PowerShell to add their files and process names to Microsoft Defender exclusions.T1573.001 · Symmetric CryptographyKothamine encrypted and decrypted messages exchanged with its command-and-control endpoint using AES-GCM.

Malware

Vendors

Products

Tools

Related Articles