Kothamine RAT Abuses Tailscale Tool to Hide Command Traffic

A newly documented Windows remote access trojan called Kothamine Agent runs more than 30 commands and routes its control traffic through Tailscale's open-source tailcat tool, leaving defenders no…

Sep 27, 2026
•
5 min read
Technobezz
Kothamine RAT Abuses Tailscale Tool to Hide Command Traffic

Don't Miss the Good Stuff

Get tech news that matters delivered weekly. Join 50,000+ readers.

A previously undocumented remote access trojan called Kothamine Agent gives attackers control over infected Windows machines, and its newer builds hide the connection that carries those instructions inside an open-source networking tool from Tailscale, according to a Malwarebytes Labs report published on September 25. The agent accepts more than 30 commands, covering tasks such as running programs and reading or altering files on the victim's system. Operators can also extend it after the fact by loading additional DLLs.

The evasion trick is the command-and-control channel. Recent versions route their traffic through tailcat, an open-source component of Tailscale, which encrypts the link and makes it harder for network defenders to inspect. Because no conventional command-and-control domain appears in that traffic, there is nothing obvious for defenders to block. Earlier Kothamine builds relied on the Tailscale VPN itself rather than tailcat, so the shift is a change in how the same malware reaches its operators.

Kothamine is written in C and C++, and most samples arrive as an injector paired with a DLL that holds the agent. That injector sets up Windows Defender exclusions through PowerShell, drops a copy of itself at %ROAMING%\MicrosoftEdgeUpdateCore.exe, and writes the agent DLL to %ROAMING%\MicrosoftEdgeUpdateCore.dll. It then injects the DLL into explorer.exe. For persistence it creates a script named up.ps1 in %TEMP% that registers a scheduled task called MicrosoftEdgeUpdateTask to run at logon. The agent itself creates a mutex named Local\KothamineAgentInstance.

Capabilities vary by build. Some samples steal browser data, and some can record through the camera and microphone. User Account Control bypass and stealer commands appear only in certain versions, and the networking components are handled differently depending on the sample: some bundle the needed tools, while others fetch them, including from GitHub and in some cases from Tailscale's official site. Recent versions also decrypt their strings inline or with XOR using a separate key for each string, a step up from earlier VirusTotal samples that carried readable strings.

The malware has been tied to malicious npm packages. A GitHub repository named in an advisory for the npm package dotnet-runtime-base is the same one that served npm-sc-legit.exe, a compiled Kothamine binary carrying data-stealing commands. Two other packages from the same developer had been removed at the time of writing. The authors also published compile instructions for something called kothamine-stub-cpp inside a package, along with a guide that discusses loading .NET assemblies, a technique not seen in the samples examined.

Researchers found no panel or builder for Kothamine, which suggests operators switch functions and commands on and off as they need them rather than working from a shared kit. The report does not name any suspected operator.

The findings land in a busy stretch for the lab. Earlier this month it described criminals turning a placeholder domain into a ClickFix trap, and before that it documented a cheap toolkit behind websites selling AI subscriptions at steep prices. A separate report covered an Android trojan, RatHat, that uses AI to lift bank logins and PINs.

Share