Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Creates up.ps1 in %TEMP% for persistence... Register-ScheduledTask 'MicrosoftEdgeUpdateTask' -Action $A -Trigger $T -RunLevel Limited -Force.
The agent ... runs PowerShell commands to add the executable and DLL to the Windows Defender exclusion list.
Creates up.ps1 in %TEMP% for persistence... Register-ScheduledTask 'MicrosoftEdgeUpdateTask' -Action $A -Trigger $T -RunLevel Limited -Force.
Recent versions decrypt strings inline or through functions that use XOR with a different key for each string.
ipconfig Executes the 'ipconfig /all' command and returns the result.
tasklist, kill Returns the processes obtained via 'tasklist /FO CSV /NH'.
Kothamine uses socket functions to connect to 127.0.0.1:18080, where tailcat is listening.
Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub... Earlier versions ... downloaded and ran the [Tailscale] installer ... or downloaded the required files directly from GitHub.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows remote-access Trojan composed commonly of an injector and an agent DLL. It injects into explorer.exe, establishes scheduled-task persistence, adds Microsoft Defender exclusions, and receives AES-GCM-encrypted commands over a local socket forwarded through tailcat; older versions used Tailscale VPN. It executes shell commands, manages processes and files, and dynamically loads operator-supplied DLL features. Certain builds include UAC bypass and data-stealing capabilities, including browser cookies, Discord/session data, gaming-related files, screenshots, camera/microphone recording, and clipboard access.
A Windows remote-access Trojan comprising an injector and an agent DLL. It injects into explorer.exe, establishes persistence through a scheduled task, adds Microsoft Defender exclusions, and receives encrypted C2 commands through tailcat or, in earlier versions, Tailscale VPN. It can execute shell commands, manipulate files and processes, load arbitrary DLL plugins, and—depending on the build—steal browser cookies, gaming-related files, clipboard data, screenshots, and camera/microphone recordings. It was distributed or linked to malicious npm packages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.