logo

TAMECAT Exposed: APT42’s Fileless Backdoor Targets Defense Chiefs

ID: 6fb1a928-6099-5a78-b69e-b86239e1e369

STIX ID: report--6fb1a928-6099-5a78-b69e-b86239e1e369

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

A Pulsedive and Israel National Digital Agency analysis links APT42 to a targeted espionage campaign using TAMECAT, a modular in-memory PowerShell backdoor that steals browser data, captures screens, and crawls files; the infection chain employs VBScript loaders and heavy obfuscation with a hardcoded AES-256 key, and operators use prolonged social engineering (e.g., WhatsApp) to gain access while blending C2 traffic through Cloudflare Workers, Telegram, Discord, and WebDAV.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.