TAMECAT is a modular PowerShell-based backdoor used in espionage operations attributed to the Iranian threat actor APT42, also tracked under aliases including Mint Sandstorm and CharmingCypress. It has been used against high-value targets such as senior government and defense officials, policy experts, individuals associated with the nuclear energy sector, and in some reporting, family members of primary targets. The malware is designed for long-term intelligence collection while minimizing forensic artifacts through largely in-memory execution and extensive use of obfuscation and legitimate Windows components.
TAMECAT is commonly delivered through highly targeted spearphishing and relationship-based social engineering. Reported lures include conference invitations, interviews, meeting documents, and other professional pretexts, sometimes reinforced through prolonged contact over personal email, corporate accounts, or WhatsApp. Observed delivery chains include malicious shortcut files disguised as documents and abuse of Windows search-ms and WebDAV to retrieve and execute follow-on stages.
The malware uses a staged, modular architecture. Early-stage components have used VBScript and PowerShell to perform environment checks, including discovery of installed antivirus products via WMI or VBScript logic, and to retrieve additional payloads. TAMECAT employs command obfuscation, Base64-encoded communications, and AES-encrypted data exchange. Reporting also describes custom handling of initialization vectors in HTTP headers and support for multiple command-and-control paths, including HTTPS as well as fallback or alternate channels over Telegram and Discord. Some variants also support FTP-based exfiltration.
TAMECAT supports remote command execution, host reconnaissance, file discovery, screenshot capture, browser data theft, Outlook mailbox data collection, and staged exfiltration. Reconnaissance functions have included collection of operating system details, hostname, domain context, privilege level, network configuration, installed software, process information, uptime, and patch status. File collection modules have targeted documents, archives, media, images, and password-database files while excluding some noisy or low-value paths.
A notable capability is theft of browser credentials and cookies from Chromium-based browsers. Reported techniques include abusing Microsoft Edge remote debugging to extract decrypted browser data and suspending Chrome to access locked profile databases for credential and cookie collection. TAMECAT has also been reported to collect Outlook mailbox cache data, capture repeated screenshots, package stolen information into archives, split large data into chunks, and exfiltrate the results over encrypted channels.
Persistence has been observed through per-user autorun mechanisms and logon-script style execution, alongside storage of victim identifiers and staged data in user-accessible locations. Defense-evasion tradecraft includes fileless execution, runtime string reconstruction, fragmented payload encoding, use of trusted binaries and LOLBins, and adaptive execution paths based on the defensive environment. Overall, TAMECAT is a mature surveillance backdoor optimized for stealthy, resilient, long-duration access in support of Iranian cyber-espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT42 used TAMECAT to collect Windows search-ms, WebDAV, browser credentials, and cookies.
APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware.
For long-term data-driven access, they deploy a sophisticated PowerShell-based backdoor known as TAMECAT... with modular components designed to facilitate data exfiltration and remote control.
Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
“GreenCharlie’s toolset centers on a multi-stage PowerShell-based malware framework, including variants known as GORBLE, TAMECAT, and POWERSTAR.”
Analysis of recent campaigns introduces TameCat, a modular, PowerShell-based backdoor used to target senior defense and government officials.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
After achieving the Initial Breach through phishing, social engineering, and supply chain attacks...
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
DarkAtlas detailed APT42's use of TAMECAT in spear-phishing attacks targeting individuals associated with the nuclear energy sector as recently as April and May 2026 via LNK files masquerading as PDF documents.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
collecting the OS and its version, hostname and domain, user and privilege level
The Processes Module captures runtime process state, including process trees, command lines, and loaded modules
The Information module fingerprints the host for targeting by collecting the OS and its version, hostname and domain, user and privilege level, network configuration, uptime, and patch status.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
the backdoor selectively gathers high-value artifacts such as documents, browser data, system general information, and screenshots.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to collect search-ms and WebDAV-related data along with browser credentials and cookies.
A modular surveillance and collection framework supporting enumeration, discovery, arbitrary command execution, browser credential and cookie theft, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
TAMECAT is a multi-function malware used in APT42 phishing campaigns. It is delivered via a WebDAV-hosted LNK/command chain and can collect browser cookies and credentials, search for files, capture screenshots, access Outlook mailbox data, run commands, package stolen information, and exfiltrate data over channels including HTTPS, Discord, and Telegram.
A modular, fileless malware that uses VBScript phishing and PowerShell-based staged delivery, decrypts payloads in memory, steals browser credentials and system information, captures screenshots, receives commands via Telegram bots, and exfiltrates encrypted data through C2 channels including dedicated servers, Discord, and Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.