TAMECAT Exposed: APT42’s Fileless Backdoor Targets Defense Chiefs
ID: 6fb1a928-6099-5a78-b69e-b86239e1e369
STIX ID: report--6fb1a928-6099-5a78-b69e-b86239e1e369
Feed Name: securityonline.info
Threat Score
A Pulsedive and Israel National Digital Agency analysis links APT42 to a targeted espionage campaign using TAMECAT, a modular in-memory PowerShell backdoor that steals browser data, captures screens, and crawls files; the infection chain employs VBScript loaders and heavy obfuscation with a hardcoded AES-256 key, and operators use prolonged social engineering (e.g., WhatsApp) to gain access while blending C2 traffic through Cloudflare Workers, Telegram, Discord, and WebDAV.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
