Skip to content
Kothamine Malware Exploits Tailcat for Evasive Remote Access

Kothamine Malware Exploits Tailcat for Evasive Remote Access

First seen 28 Sep 2026, 22:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 23:08 UTC
  • •Kothamine is a RAT using tailcat for encrypted C2 communications.
  • •The malware is linked to malicious npm packages, notably dotnet-runtime-base.
  • •Users should rigorously vet npm packages to avoid infection.

Kothamine is an undocumented remote-access Trojan (RAT) discovered in malicious npm packages. It employs Tailscale's tailcat to create encrypted command-and-control channels, evading traditional network detection methods. The malware allows attackers to control infected Windows systems, execute commands, and steal data. Researchers linked Kothamine to the npm package dotnet-runtime-base, revealing a multi-stage execution process that includes an injector targeting explorer.exe. The malware's architecture supports modular plugins for additional capabilities. Users are advised to thoroughly vet npm packages before installation and monitor for unauthorized use of networking tools. The malware has been active since at least July 2026, with various versions exhibiting different capabilities. Current recommendations include isolating affected systems and performing memory forensics to identify the Kothamine Agent DLLs.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-01
Kothamine development began
Kothamine appears to have been in development or distribution since at least July 2026.
Malwarebytes
2026-09-25
Kothamine reported by Malwarebytes
Malwarebytes disclosed the Kothamine RAT, detailing its capabilities and distribution methods via npm packages.
Malwarebytes
2026-09-28
Kothamine analysis published by Socprime
Socprime provided further analysis on Kothamine, emphasizing its evasion tactics and attack methods.
Socprime

More articles in this cluster (2)

Following this threat?

Track Kothamine in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed