Socprime Kothamine Malware Exploits Tailcat for Evasive Remote Access
Article Content
- •Kothamine is a RAT using tailcat for encrypted C2 communications.
- •The malware is linked to malicious npm packages, notably dotnet-runtime-base.
- •Users should rigorously vet npm packages to avoid infection.
Kothamine is an undocumented remote-access Trojan (RAT) discovered in malicious npm packages. It employs Tailscale's tailcat to create encrypted command-and-control channels, evading traditional network detection methods. The malware allows attackers to control infected Windows systems, execute commands, and steal data. Researchers linked Kothamine to the npm package dotnet-runtime-base, revealing a multi-stage execution process that includes an injector targeting explorer.exe. The malware's architecture supports modular plugins for additional capabilities. Users are advised to thoroughly vet npm packages before installation and monitor for unauthorized use of networking tools. The malware has been active since at least July 2026, with various versions exhibiting different capabilities. Current recommendations include isolating affected systems and performing memory forensics to identify the Kothamine Agent DLLs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Kothamine in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…