Kothamine malware uses Tailscale’s tailcat to evade network detection

Executive Summary

Kothamine, a new malware strain, hijacks the legitimate Tailscale tool tailcat to establish an encrypted command‑and‑control channel. By leveraging Tailscale’s peer‑to‑peer networking, the malware receives attacker commands without contacting any external malicious domains, thereby bypassing traditional network detection and blocking mechanisms.


Intelligence Metadata - Source Publisher: Malwarebytes Labs - Published Date: 2026-09-25T14:57:29+00:00 - Category: malware

Original Description: Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block.

"To accomplish great things, we must dream as well as act."

— Anatole France
Source: Malwarebytes Labs