# Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages

> Kothamine, an undocumented Windows RAT with 30+ operator commands, is distributed via the malicious npm package dotnet-runtime-base and a GitHub payload repository. Recent builds extract and launch Tailscale's open-source tailcat CLI to tunnel AES-GCM-encrypted C2 to an operator-controlled node instead of registering a full Tailscale VPN device, defeating conventional network-based C2 detection.

- **Published:** 2026-09-26T00:00:00Z
- **Last reviewed:** 2026-09-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2665
- **ID:** TL-2026-2665
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Kothamine Agent is an undocumented C/C++ Windows remote-access Trojan first observed via VirusTotal uploads and GitHub commit activity in July 2026. It is distributed through the malicious npm package dotnet-runtime-base (versions 1.0.4-1.0.5, published 2026-07-13, tracked as GHSA-9gr8-wg29-9wvv / OSV MAL-2026-10217, discovered by Amazon Inspector), whose Windows-only postinstall script (install.js) writes a PowerShell script to the temp directory and uses WebClient.DownloadFile to silently retrieve and launch npm-sc-legit.exe from an unauthorized GitHub account (github.com/cphc811-ui), which also hosts build/compilation instructions for a companion project named kothamine-stub-cpp. At least two other packages from the same npm publisher were removed by npm.

On execution, an injector adds Microsoft Defender path/process exclusions, copies itself to %ROAMING%\MicrosoftEdgeUpdateCore.exe, extracts an agent DLL to %ROAMING%\MicrosoftEdgeUpdateCore.dll, writes a launcher script to %TEMP%\up.ps1, registers persistence via a scheduled task ("MicrosoftEdgeUpdateTask", triggered AtLogOn, RunLevel Limited), and injects the agent DLL into explorer.exe using OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread/LoadLibraryA. The running agent creates a single-instance mutex (Local\KothamineAgentInstance) and, in recent builds, decrypts internal strings using XOR at runtime.

The agent exposes 30+ operator commands covering system/process/network enumeration (sysinfo, systeminfo, tasklist, ipconfig, ping), file operations (mkdir/rmdir/cp/mv/ls/readfile/writefile_*/delfile/download), shell execution (exec, shell_exec), and data theft (getdiscord, getsessions for browser cookies, screenshot/screenshare, camera, plus clipboard, Steam and Minecraft configuration theft, and microphone recording). A dynamic plugin system (load_feature/exec_feature/list_features/unload_feature) lets the operator push a base64-encoded DLL that is written to a temp path (GetTempPath/SHGetFolderPathA, falling back to C:\Windows\Temp), loaded via LoadLibraryA, and resolved through a GetFeatureApi export exposing init/exec/cleanup callbacks - allowing capability expansion without redeploying the core agent.

Some builds bypass UAC via fodhelper.exe to run an elevated.ps1 PowerShell script, which launches tailscaled.exe from a portable Tailscale install and issues "tailscale up" with an auth key, polling the resulting IP for a 100.x.x.x prefix (45 iterations / ~90s timeout) to confirm the Tailscale network came up. Earlier Kothamine builds used this full Tailscale VPN client (tailscaled.exe, tailscale.exe, tailscale-ipn.exe, wintun.dll) connecting over the Tailscale network to an operator node on port 4444. Recent builds instead extract Tailscale's open-source tailcat utility to %ROAMING%\TailscalePortable\tailcat.exe and launch it via CreateProcessA with arguments equivalent to "forward tcp 18080:4444", forwarding a local listener (port 18080) to the operator's port 4444 over tailcat's data plane (WireGuard + NAT traversal + DERP relay, no Tailscale control plane, no account/device registration required). C2 messages are encrypted with AES-GCM using a hardcoded 32-byte key base64-decoded from "mrowPsW2P5kzFGCNWeKAd+kYpo8Yy5c2pzaOSRuzisU="; the agent identifies itself to the operator with a JSON blob of the form {"name":"base_<rand>","os":"Windows","ip":"0.0.0.0","auth_token":"...","type":"base"}. Because tailcat rides a trusted, already-encrypted transport with no conventional C2 domain to block, network defenses are unlikely to flag the traffic.

Malwarebytes (analyst Gabriele Orini) published the first public technical writeup on 2026-09-25. No specific threat actor, group, or nation-state attribution has been established; the only identifying artifact is the npm/GitHub publisher handle cphc811-ui. Activity has been continuous since at least July 2026 with incremental feature additions and obfuscation improvements, and remains active as of the report's publication date.

## MITRE ATT&CK

- T1588.002 Tool
- T1195.002 Compromise Software Supply Chain
- T1059.007 JavaScript
- T1059.001 PowerShell
- T1129 Shared Modules
- T1053.005 Scheduled Task
- T1548.002 Bypass User Account Control
- T1055.001 Dynamic-link Library Injection
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1057 Process Discovery
- T1113 Screen Capture
- T1123 Audio Capture
- T1125 Video Capture
- T1539 Steal Web Session Cookie
- T1219 Remote Access Tools
- T1572 Protocol Tunneling
- T1573.001 Symmetric Cryptography

## Sources

- [Kothamine malware uses Tailscale's tailcat to evade network detection](https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection)
- [GHSA-9gr8-wg29-9wvv: dotnet-runtime-base embedded malicious code](https://github.com/advisories/GHSA-9gr8-wg29-9wvv)
- [MAL-2026-10217: dotnet-runtime-base (npm)](https://osv.dev/vulnerability/MAL-2026-10217)
- [Kothamine RAT Abuses Tailscale Tailcat for Covert Windows C2](https://mallory.ai/stories/01a0d958-7be6-785c-a1b1-b8a0f82024b1)
- [Kothamine malware uses Tailscale's tailcat to evade network detection (aggregator repost)](https://malware.news/t/kothamine-malware-uses-tailscale-s-tailcat-to-evade-network-detection/125898)
- [Tailcat: An open-source CLI for Tailscale's WireGuard, NAT traversal, and DERP](https://tailscale.com/blog/tailcat)
- [GitHub - tailscale/tailcat](https://github.com/tailscale/tailcat)
- [cphc811-ui GitHub account (malicious payload/build-instructions host)](https://github.com/cphc811-ui/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2665
