Skip to content
Kothamine Malware Abuses Tailcat to Evade Detection

Kothamine Malware Abuses Tailcat to Evade Detection

Socprime • September 28, 2026

Kothamine is an undocumented remote-access Trojan (RAT) distributed via malicious npm packages. It utilizes the open-source tool tailcat from Tailscale to establish encrypted command-and-control (C2) channels, bypassing traditional network inspection. The malware features a modular plugin system allowing attackers to extend capabilities such as data theft and system control.

Researchers identified Kothamine through the analysis of malicious npm packages like dotnet-runtime-base. The investigation revealed a multi-stage execution process involving an injector that targets explorer.exe and uses tailcat for resilient communications. Technical analysis showed the use of AES-GCM for command encryption and a plugin architecture for loading additional DLLs.

Users should rigorously vet npm packages by checking repository history, maintainers, and dependency reputation before installation. Organizations should implement strict controls over developer environments and monitor for unauthorized use of networking tools like Tailscale or tailcat. Regular scanning for unauthorized scheduled tasks and Windows Defender exclusion changes is also recommended.

Upon detection, isolate affected systems to prevent lateral movement and data exfiltration via the tailcat channel. Perform memory forensics on explorer.exe to identify injected Kothamine Agent DLLs. Audit Windows Defender exclusion lists and scheduled tasks for persistence mechanisms like ‘MicrosoftEdgeUpdateTask’.

Attack Narrative & Commands: An adversary aims to establish persistence and evade network detection by deploying the Kothamine malware. First, the attacker mimics a legitimate update process by moving a malicious payload to %APPDATA%MicrosoftEdgeUpdateCore.exe . To avoid detection during the injection phase, the attacker executes a PowerShell command with hidden window flags. This command is designed to call VirtualAllocEx and CreateRemoteThread to inject code into a target process, facilitating encrypted C2 communication via tailcat.exe .

Attack Narrative & Commands: An adversary aims to establish persistence and evade network detection by deploying the Kothamine malware. First, the attacker mimics a legitimate update process by moving a malicious payload to %APPDATA%MicrosoftEdgeUpdateCore.exe . To avoid detection during the injection phase, the attacker executes a PowerShell command with hidden window flags. This command is designed to call VirtualAllocEx and CreateRemoteThread to inject code into a target process, facilitating encrypted C2 communication via tailcat.exe .

Regression Test Script: # Kothamine Simulation Script $appData = [System.Environment]::GetFolderPath('ApplicationData') $targetPath = Join-Path $appData "MicrosoftEdgeUpdateCore.exe" $maliciousPayload = "C:WindowsSystem32calc.exe" # Using calc as a dummy payload # 1. Simulate dropping the malicious binary (T1218) Copy-Item $maliciousPayload $targetPath -Force Write-Host "[+] Payload dropped to $targetPath" # 2. Simulate the execution of the injection command (T1055) # Note: We are simulating the command line strings that the rule looks for. # Since we cannot easily call 'OpenProcess' from a raw CLI string without a script, # we simulate the Command Line telemetry that would be captured by Sysmon/EDR. $cmd = "powershell -NoP -NonI -W Hidden -Exec Bypass -Command `"`$mem = [Runtime.InteropServices.Marshal]::AllocHGlobal(1024); [Runtime.InteropServices.Marshal]::WriteProcessMemory(...)`"" Start-Process -FilePath $targetPath -ArgumentList $cmd Write-Host "[+] Malicious command executed via $targetPath"

Regression Test Script:

Cleanup Commands: # Cleanup the simulated artifacts $appData = [System.Environment]::GetFolderPath('ApplicationData') $targetPath = Join-Path $appData "MicrosoftEdgeUpdateCore.exe" if (Test-Path $targetPath) { Remove-Item $targetPath -Force Write-Host "[+] Cleaned up $targetPath" }

Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.