Skip to content
DnsLister Forum

Where domain hunters compare notes

Kothamine malware uses Tailscale’s tailcat to evade network detection

This is a clever abuse of trust. Kothamine is leveraging tailcat, Tailscale’s legitimate SSH-like proxy tool, to establish C2 over an encrypted WireGuard tunnel. Because the traffic is encrypted and routed through Tailscale’s infrastructure, there are no malicious domains or IPs to block at the network perimeter—standard DNS or IP-based detections will miss this entirely.

Technical Breakdown: – Tactic: Command and Control (TA0011) – Technique: Protocol Tunneling (T1572) / Encrypted Channel (T1573) – Tool Abuse: tailcat (legitimate Tailscale utility) used to proxy attacker commands over the Tailscale mesh network – Detection Gap: No static IOCs (domains/IPs) to block; traffic blends with legitimate Tailscale usage – Target: Likely initial access via phishing or compromised credentials to install Tailscale client

Defense: Monitor for unauthorized Tailscale node enrollments and unexpected tailcat process executions. Restrict installation of mesh VPN clients via AppLocker/Windows Defender Application Control. If Tailscale is not approved in your environment, block the binary and domains (tailscale.com, login.tailscale.com) at the proxy level.

Source: https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *