← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 25, 2026 · 14:57via Malwarebytes Labs

Kothamine malware uses Tailscale’s tailcat to evade network detection

Brief

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent . It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone.

We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat , an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.

Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July.

Read more on Malwarebytes Labs→