Kothamine Malware Leverages Tailcat for Stealthy Network Access
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
Kothamine is an undocumented remote-access Trojan (RAT) distributed via malicious npm packages. It utilizes the open-source tool tailcat from Tailscale to establish encrypted command-and-control (C2) channels, bypassing traditional network inspection. The malware features a modular plugin system allowing attackers to extend capabilities such as data theft and system control.
Investigation
Researchers identified Kothamine through the analysis of malicious npm packages like dotnet-runtime-base. The investigation revealed a multi-stage execution process involving an injector that targets explorer.exe and uses tailcat for resilient communications. Technical analysis showed the use of AES-GCM for command encryption and a plugin architecture for loading additional DLLs.
Mitigation
Users should rigorously vet npm packages by checking repository history, maintainers, and dependency reputation before installation. Organizations should implement strict controls over developer environments and monitor for unauthorized use of networking tools like Tailscale or tailcat. Regular scanning for unauthorized scheduled tasks and Windows Defender exclusion changes is also recommended.
Response
Upon detection, isolate affected systems to prevent lateral movement and data exfiltration via the tailcat channel. Perform memory forensics on explorer.exe to identify injected Kothamine Agent DLLs. Audit Windows Defender exclusion lists and scheduled tasks for persistence mechanisms like ‘MicrosoftEdgeUpdateTask’.
Attack Flow
Detections
The Possibility of Execution Through Hidden PowerShell Command Lines (via cmdline)
Possible System Network Configuration Discovery (via cmdline)
Possible Execution by Use of Short Script Name (via cmdline)
Alternative Remote Access / Management Software (via process_creation)
Possible Scheduled Task Creation (via powershell)
Windows Defender Preferences Suspicious Changes (via powershell)
Alternative Remote Access / Management Software (via system)
Alternative Remote Access / Management Software (via audit)
Kothamine Tailcat Local Port Communication Detection [Windows Network Connection]
Kothamine Malware Detection via MicrosoftEdgeUpdateCore and Tailcat [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An adversary aims to establish persistence and evade network detection by deploying the Kothamine malware. First, the attacker mimics a legitimate update process by moving a malicious payload to
%APPDATA%MicrosoftEdgeUpdateCore.exe. To avoid detection during the injection phase, the attacker executes a PowerShell command with hidden window flags. This command is designed to callVirtualAllocExandCreateRemoteThreadto inject code into a target process, facilitating encrypted C2 communication viatailcat.exe. -
Regression Test Script:
# Kothamine Simulation Script $appData = [System.Environment]::GetFolderPath('ApplicationData') $targetPath = Join-Path $appData "MicrosoftEdgeUpdateCore.exe" $maliciousPayload = "C:WindowsSystem32calc.exe" # Using calc as a dummy payload # 1. Simulate dropping the malicious binary (T1218) Copy-Item $maliciousPayload $targetPath -Force Write-Host "[+] Payload dropped to $targetPath" # 2. Simulate the execution of the injection command (T1055) # Note: We are simulating the command line strings that the rule looks for. # Since we cannot easily call 'OpenProcess' from a raw CLI string without a script, # we simulate the Command Line telemetry that would be captured by Sysmon/EDR. $cmd = "powershell -NoP -NonI -W Hidden -Exec Bypass -Command `"`$mem = [Runtime.InteropServices.Marshal]::AllocHGlobal(1024); [Runtime.InteropServices.Marshal]::WriteProcessMemory(...)`"" Start-Process -FilePath $targetPath -ArgumentList $cmd Write-Host "[+] Malicious command executed via $targetPath" -
Cleanup Commands:
# Cleanup the simulated artifacts $appData = [System.Environment]::GetFolderPath('ApplicationData') $targetPath = Join-Path $appData "MicrosoftEdgeUpdateCore.exe" if (Test-Path $targetPath) { Remove-Item $targetPath -Force Write-Host "[+] Cleaned up $targetPath" }