logo

TAMECAT - Analysis of an Iranian PowerShell-Based Backdoor

ID: 73a7cd15-9d3b-5c4a-98c4-8fc12609f73d

STIX ID: report--73a7cd15-9d3b-5c4a-98c4-8fc12609f73d

Feed Name: Pulsedive Blog

Threat Score
85/100

Date Published: 2026-01-29

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

*TAMECAT* is a modular PowerShell-based espionage malware used by APT42 that employs a VBScript/PowerShell loader chain to deploy in-memory modules capable of browser data extraction, screen captures, and data exfiltration via encrypted POSTs to attacker-controlled endpoints; the report includes technical analysis of the loader and decryption routines, observed C2/hosting domains, MITRE ATT&CK mappings, and recommended mitigations such as EDR/AV deployment and expanded PowerShell logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.