TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome
ID: f0f8527e-31ee-553c-87d1-3c0926a11b80
STIX ID: report--f0f8527e-31ee-553c-87d1-3c0926a11b80
Feed Name: cybersecurityNews.com
TAMECAT is a sophisticated PowerShell-based credential-stealing malware linked to Iranian APT42 that uses WhatsApp social engineering, VBScript/LNK droppers, and multiple C2 channels (Telegram, Discord, Firebase, Cloudflare) to deliver modular payloads. It extracts credentials from Edge and Chrome (using remote debugging and process suspension), maintains persistence via logon scripts and registry run keys, chunks and exfiltrates stolen data over encrypted channels (AES) and protocols like FTP/HTTPS, and employs in-memory operations and obfuscation to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
