Kothamine malware uses Tailscale’s tailcat to evade network detection
Brief
We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent . It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone.
We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat , an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.
Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July.
