Threat reportMalwareTL-2026-2665
Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages
Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2 (TL-2026-2665), also tracked as Kothamine Agent, is a high-severity malware campaign, first published 2026-09-26. It has no confirmed attribution, affects Unidentified npm publisher (account/package removed), maps to 19 MITRE ATT&CK techniques (T1027, T1053.005, T1055.001), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-2665
- Threat ID
- TL-2026-2665
- Also known as
- Kothamine Agent, cphc811-ui campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2
Malware and tooling: Kothamine, Kothamine Agent, Tailscale VPN client (tailscaled.exe / tailscale.exe / tailscale-ipn.exe / wintun.dll), tailcat
How Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2 works
Kothamine, an undocumented Windows RAT with 30+ operator commands, is distributed via the malicious npm package dotnet-runtime-base and a GitHub payload repository. Recent builds extract and launch Tailscale's open-source tailcat CLI to tunnel AES-GCM-encrypted C2 to an operator-controlled node instead of registering a full Tailscale VPN device, defeating conventional network-based C2 detection.
Kothamine Agent is an undocumented C/C++ Windows remote-access Trojan first observed via VirusTotal uploads and GitHub commit activity in July 2026. It is distributed through the malicious npm package dotnet-runtime-base (versions 1.0.4-1.0.5, published 2026-07-13, tracked as GHSA-9gr8-wg29-9wvv / OSV MAL-2026-10217, discovered by Amazon Inspector), whose Windows-only postinstall script (install.js) writes a PowerShell script to the temp directory and uses WebClient.DownloadFile to silently retrieve and launch npm-sc-legit.exe from an unauthorized GitHub account (github.com/cphc811-ui), which also hosts build/compilation instructions for a companion project named kothamine-stub-cpp. At least two other packages from the same npm publisher were removed by npm.
On execution, an injector adds Microsoft Defender path/process exclusions, copies itself to %ROAMING%\MicrosoftEdgeUpdateCore.exe, extracts an agent DLL to %ROAMING%\MicrosoftEdgeUpdateCore.dll, writes a launcher script to %TEMP%\up.ps1, registers persistence via a scheduled task ("MicrosoftEdgeUpdateTask", triggered AtLogOn, RunLevel Limited), and injects the agent DLL into explorer.exe using OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread/LoadLibraryA. The running agent creates a single-instance mutex (Local\KothamineAgentInstance) and, in recent builds, decrypts internal strings using XOR at runtime.
The agent exposes 30+ operator commands covering system/process/network enumeration (sysinfo, systeminfo, tasklist, ipconfig, ping), file operations (mkdir/rmdir/cp/mv/ls/readfile/writefile_*/delfile/download), shell execution (exec, shell_exec), and data theft (getdiscord, getsessions for browser cookies, screenshot/screenshare, camera, plus clipboard, Steam and Minecraft configuration theft, and microphone recording). A dynamic plugin system (load_feature/exec_feature/list_features/unload_feature) lets the operator push a base64-encoded DLL that is written to a temp path (GetTempPath/SHGetFolderPathA, falling back to C:\Windows\Temp), loaded via LoadLibraryA, and resolved through a GetFeatureApi export exposing init/exec/cleanup callbacks - allowing capability expansion without redeploying the core agent.
Some builds bypass UAC via fodhelper.exe to run an elevated.ps1 PowerShell script, which launches tailscaled.exe from a portable Tailscale install and issues "tailscale up" with an auth key, polling the resulting IP for a 100.x.x.x prefix (45 iterations / ~90s timeout) to confirm the Tailscale network came up. Earlier Kothamine builds used this full Tailscale VPN client (tailscaled.exe, tailscale.exe, tailscale-ipn.exe, wintun.dll) connecting over the Tailscale network to an operator node on port 4444. Recent builds instead extract Tailscale's open-source tailcat utility to %ROAMING%\TailscalePortable\tailcat.exe and launch it via CreateProcessA with arguments equivalent to "forward tcp 18080:4444", forwarding a local listener (port 18080) to the operator's port 4444 over tailcat's data plane (WireGuard + NAT traversal + DERP relay, no Tailscale control plane, no account/device registration required). C2 messages are encrypted with AES-GCM using a hardcoded 32-byte key base64-decoded from "mrowPsW2P5kzFGCNWeKAd+kYpo8Yy5c2pzaOSRuzisU="; the agent identifies itself to the operator with a JSON blob of the form {"name":"base_<rand>","os":"Windows","ip":"0.0.0.0","auth_token":"...","type":"base"}. Because tailcat rides a trusted, already-encrypted transport with no conventional C2 domain to block, network defenses are unlikely to flag the traffic.
Malwarebytes (analyst Gabriele Orini) published the first public technical writeup on 2026-09-25. No specific threat actor, group, or nation-state attribution has been established; the only identifying artifact is the npm/GitHub publisher handle cphc811-ui. Activity has been continuous since at least July 2026 with incremental feature additions and obfuscation improvements, and remains active as of the report's publication date.
MITRE ATT&CK techniques used in TL-2026-2665
Defense Evasion
T1027 Obfuscated Files or Information; T1055.001 Dynamic-link Library Injection
Persistence
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1059.007 JavaScript; T1129 Shared Modules
Collection
T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture
Initial Access
T1195.002 Compromise Software Supply Chain
Command and Control
T1219 Remote Access Tools; T1572 Protocol Tunneling; T1573.001 Symmetric Cryptography
credential-access
T1539 Steal Web Session Cookie
Privilege Escalation
T1548.002 Bypass User Account Control
Resource Development
defense-impairment
Affected products and versions in Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2
- Unidentified npm publisher (account/package removed) — dotnet-runtime-base
Vulnerable versions: 1.0.4; 1.0.5 - Generic — Windows developer/build workstations with Node.js and npm
Vulnerable versions: any host that ran `npm install dotnet-runtime-base` at 1.0.4-1.0.5
Remediation for Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2
Patches
- No vendor patch applies - dotnet-runtime-base is a malicious package with no legitimate patched release; remediation is removal, not patching (GHSA-9gr8-wg29-9wvv)
Immediate actions
- Remove/block the npm package 'dotnet-runtime-base' (versions 1.0.4 and 1.0.5) across all developer workstations and CI/CD pipelines
- Hunt for SHA-256 ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0 (injector) and 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c (agent DLL)
- Hunt for file artifacts %ROAMING%\MicrosoftEdgeUpdateCore.exe, %ROAMING%\MicrosoftEdgeUpdateCore.dll, and %ROAMING%\TailscalePortable\tailcat.exe
- Check Windows Task Scheduler for an unexpected 'MicrosoftEdgeUpdateTask' entry (AtLogOn trigger, RunLevel Limited) pointing at a Roaming AppData executable
- Treat any host that installed dotnet-runtime-base 1.0.4/1.0.5 as fully compromised and rotate all secrets/keys handled on that host from a separate, uncompromised device, per GHSA-9gr8-wg29-9wvv guidance
Workarounds
- Block execution of tailcat.exe and unapproved Tailscale binaries via application allow-listing/EDR
- Restrict PowerShell execution policy and enable ScriptBlock/Module logging to catch elevated.ps1/up.ps1-style launcher scripts and fodhelper.exe-based UAC bypass chains
Longer-term hardening
- Add install-time postinstall-script auditing / dependency vetting to CI/CD so packages that download and silently execute binaries are blocked before merge
- Monitor endpoints for unauthorized tailcat.exe or portable Tailscale client execution and unexpected outbound WireGuard/DERP traffic from developer or build workstations
- Alert on Microsoft Defender exclusion-path additions made via PowerShell outside of approved change management
- Enforce a private/mirrored npm registry with package allow-listing for build and developer environments
Weaknesses (CWE) in Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2
Timeline of Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2
- Malicious npm package dotnet-runtime-base (versions 1.0.4-1.0.5) published to the npm registry with a Windows-only postinstall script that downloads and launches npm-sc-legit.exe; later tracked as GHSA-9gr8-wg29-9wvv / OSV MAL-2026-10217, credited to Amazon Inspector.
- Earliest Kothamine agent/injector samples appear on VirusTotal, with corresponding commit activity on the cphc811-ui GitHub repository hosting kothamine-stub-cpp build instructions.
- Earlier Kothamine builds are observed installing the full Tailscale VPN client (tailscaled.exe, tailscale.exe, tailscale-ipn.exe, wintun.dll) and connecting to an operator node on port 4444 over the Tailscale network.
- Kothamine builds incorporate a fodhelper.exe-based UAC bypass that silently runs elevated.ps1 to launch the Tailscale client with elevated privileges and an auth key.
- Recent Kothamine builds replace the full Tailscale VPN client with the lightweight open-source tailcat CLI, tunneling AES-GCM-encrypted C2 without registering a Tailscale account or device.
- TL-Intel-Harness ingests the Malwarebytes report from the RSS backlog and opens threat TL-2026-2665 for analysis.
- Malwarebytes Threat Intelligence (Gabriele Orini) publishes the first public technical analysis, 'Kothamine malware uses Tailscale's tailcat to evade network detection.'
Sources cited for Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2
- Kothamine malware uses Tailscale's tailcat to evade network detection
- GHSA-9gr8-wg29-9wvv: dotnet-runtime-base embedded malicious code
- MAL-2026-10217: dotnet-runtime-base (npm)
- Kothamine RAT Abuses Tailscale Tailcat for Covert Windows C2
- Kothamine malware uses Tailscale's tailcat to evade network detection (aggregator repost)
- Tailcat: An open-source CLI for Tailscale's WireGuard, NAT traversal, and DERP
- GitHub - tailscale/tailcat
- cphc811-ui GitHub account (malicious payload/build-instructions host)
Detection coverage for TL-2026-2665
As of 2026-09-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2665 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.