Security reports say the TAMECAT PowerShell-based backdoor is being used to harvest saved login credentials from Microsoft Edge and Google Chrome. The malware is described as targeting browser-stored usernames and passwords, putting enterprise and personal accounts at risk if infected systems are compromised.
Coverage across multiple security outlets identifies TAMECAT as a credential-theft backdoor built around PowerShell, highlighting its ability to exfiltrate sensitive browser data from widely used Chromium-based browsers. The activity underscores the continued use of native scripting tools for stealthy post-compromise access and data theft, with browser credential stores remaining a high-value target for attackers seeking account takeover and broader network intrusion.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Multiple reports disclosed the TAMECAT PowerShell-based backdoor as malware capable of stealing login credentials from Microsoft Edge and Google Chrome. The references do not provide a more specific event date beyond the publication day.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cyberpress.org
Open sourcegbhackers.com
Open sourcemalwaretips.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.