SOC Prime Bias: High

28 Sep 2026 14:55 UTC

Kothamine Malware Leverages Tailcat for Stealthy Network Access

Author Photo
SOC Prime Team linkedin icon Follow
Kothamine Malware Leverages Tailcat for Stealthy Network Access
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

Kothamine is an undocumented remote-access Trojan (RAT) distributed via malicious npm packages. It utilizes the open-source tool tailcat from Tailscale to establish encrypted command-and-control (C2) channels, bypassing traditional network inspection. The malware features a modular plugin system allowing attackers to extend capabilities such as data theft and system control.

Investigation

Researchers identified Kothamine through the analysis of malicious npm packages like dotnet-runtime-base. The investigation revealed a multi-stage execution process involving an injector that targets explorer.exe and uses tailcat for resilient communications. Technical analysis showed the use of AES-GCM for command encryption and a plugin architecture for loading additional DLLs.

Mitigation

Users should rigorously vet npm packages by checking repository history, maintainers, and dependency reputation before installation. Organizations should implement strict controls over developer environments and monitor for unauthorized use of networking tools like Tailscale or tailcat. Regular scanning for unauthorized scheduled tasks and Windows Defender exclusion changes is also recommended.

Response

Upon detection, isolate affected systems to prevent lateral movement and data exfiltration via the tailcat channel. Perform memory forensics on explorer.exe to identify injected Kothamine Agent DLLs. Audit Windows Defender exclusion lists and scheduled tasks for persistence mechanisms like ‘MicrosoftEdgeUpdateTask’.

Attack Flow

Detections

The Possibility of Execution Through Hidden PowerShell Command Lines (via cmdline)

SOC Prime Team
28 Sep 2026

Possible System Network Configuration Discovery (via cmdline)

SOC Prime Team
28 Sep 2026

Possible Execution by Use of Short Script Name (via cmdline)

SOC Prime Team
28 Sep 2026

Alternative Remote Access / Management Software (via process_creation)

SOC Prime Team
28 Sep 2026

Possible Scheduled Task Creation (via powershell)

SOC Prime Team
28 Sep 2026

Windows Defender Preferences Suspicious Changes (via powershell)

SOC Prime Team
28 Sep 2026

Alternative Remote Access / Management Software (via system)

SOC Prime Team
28 Sep 2026

Alternative Remote Access / Management Software (via audit)

SOC Prime Team
28 Sep 2026

Kothamine Tailcat Local Port Communication Detection [Windows Network Connection]

SOC Prime AI Rules
28 Sep 2026

Kothamine Malware Detection via MicrosoftEdgeUpdateCore and Tailcat [Windows Process Creation]

SOC Prime AI Rules
28 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: An adversary aims to establish persistence and evade network detection by deploying the Kothamine malware. First, the attacker mimics a legitimate update process by moving a malicious payload to %APPDATA%MicrosoftEdgeUpdateCore.exe. To avoid detection during the injection phase, the attacker executes a PowerShell command with hidden window flags. This command is designed to call VirtualAllocEx and CreateRemoteThread to inject code into a target process, facilitating encrypted C2 communication via tailcat.exe.

  • Regression Test Script:

    # Kothamine Simulation Script
    $appData = [System.Environment]::GetFolderPath('ApplicationData')
    $targetPath = Join-Path $appData "MicrosoftEdgeUpdateCore.exe"
    $maliciousPayload = "C:WindowsSystem32calc.exe" # Using calc as a dummy payload
    
    # 1. Simulate dropping the malicious binary (T1218)
    Copy-Item $maliciousPayload $targetPath -Force
    Write-Host "[+] Payload dropped to $targetPath"
    
    # 2. Simulate the execution of the injection command (T1055)
    # Note: We are simulating the command line strings that the rule looks for.
    # Since we cannot easily call 'OpenProcess' from a raw CLI string without a script, 
    # we simulate the Command Line telemetry that would be captured by Sysmon/EDR.
    
    $cmd = "powershell -NoP -NonI -W Hidden -Exec Bypass -Command `"`$mem = [Runtime.InteropServices.Marshal]::AllocHGlobal(1024); [Runtime.InteropServices.Marshal]::WriteProcessMemory(...)`""
    
    Start-Process -FilePath $targetPath -ArgumentList $cmd
    Write-Host "[+] Malicious command executed via $targetPath"
  • Cleanup Commands:

    # Cleanup the simulated artifacts
    $appData = [System.Environment]::GetFolderPath('ApplicationData')
    $targetPath = Join-Path $appData "MicrosoftEdgeUpdateCore.exe"
    if (Test-Path $targetPath) {
        Remove-Item $targetPath -Force
        Write-Host "[+] Cleaned up $targetPath"
    }