Kothamine malware uses Tailscale’s tailcat to evade network detection (opens in a new tab)
Why readDocuments an undocumented Windows RAT that routes its C2 over Tailscale's tailcat, leaving defenders with no C2 domain to block and an encrypted tunnel they cannot inspect.
Kothamine Agent is a previously undocumented RAT supporting 30-plus commands: arbitrary command execution, file read/write, modular capability loading, and in some builds browser credential theft plus camera and microphone capture. Recent versions abandon the full Tailscale VPN client for tailcat, Tailscale's open-source component, to carry commands over an encrypted tailnet connection, which removes the conventional C2 domain or IP that network detection normally keys on. Distribution is tied to malicious npm packages, putting developer workstations in the blast radius, and VirusTotal uploads plus GitHub commit history put development back to at least July 2026; depending on build, the networking tooling is bundled or pulled from GitHub at runtime.
Indicators3
- Hashes
ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee074eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c- Domains
third-party[.]com