TAMECAT is a modular PowerShell-based backdoor used by the Iranian state-sponsored cyberespionage group APT42 against Windows systems. It supports arbitrary PowerShell and C# execution, retrieval of additional components, remote control, reconnaissance, and sensitive-data collection. Its targeting includes senior government and defense officials, policy experts, individuals associated with nuclear energy, and people affiliated with nongovernmental organizations, media, academia, and legal services.
TAMECAT is delivered through targeted spear-phishing and prolonged trust-building social engineering, including email and WhatsApp conversations using conference, meeting, and interview invitations. Infection chains have used malicious macro-enabled documents and Windows shortcuts disguised as PDF documents. Some campaigns abuse the Windows search-ms protocol handler to expose malicious shortcuts through an attacker-controlled WebDAV share. VBScript downloaders query installed antivirus products through Windows Management Instrumentation and select subsequent execution methods according to the results.
The backdoor collects host and network information, enumerates security software, searches for valuable files, captures screenshots, and steals browser credentials and cookies. Browser collection includes Microsoft Edge remote debugging and temporary suspension of Google Chrome to access profile databases. It also collects Outlook mailbox caches and stages stolen files in compressed archives. Persistence mechanisms include per-user registry Run keys and logon scripts.
TAMECAT executes much of its functionality in memory and uses obfuscated scripts, encoded payloads, and legitimate Windows utilities to reduce forensic visibility. Command-and-control implementations use HTTP or HTTPS, with variants supporting Telegram and Discord. Communications employ Base64 encoding and AES encryption. Collected data can be divided into chunks and exfiltrated through command-and-control channels or FTP, while multiple communication options provide resilience.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers used malicious emails to deliver two custom backdoors, named Nicecurl and Tamecat, which allowed them to execute commands and steal sensitive data from the compromised systems.
APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware.
For long-term data-driven access, they deploy a sophisticated PowerShell-based backdoor known as TAMECAT... with modular components designed to facilitate data exfiltration and remote control.
Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
“GreenCharlie’s toolset centers on a multi-stage PowerShell-based malware framework, including variants known as GORBLE, TAMECAT, and POWERSTAR.”
Analysis of recent campaigns introduces TameCat, a modular, PowerShell-based backdoor used to target senior defense and government officials.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
After achieving the Initial Breach through phishing, social engineering, and supply chain attacks...
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
TAMECAT is a PowerShell toehold that can execute arbitrary PowerShell or C# content.
DarkAtlas detailed APT42's use of TAMECAT in spear-phishing attacks targeting individuals associated with the nuclear energy sector as recently as April and May 2026 via LNK files masquerading as PDF documents.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
collecting the OS and its version, hostname and domain, user and privilege level
The Information module fingerprints the host for targeting by collecting the OS and its version, hostname and domain, user and privilege level, network configuration, uptime, and patch status.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
The attack chain culminates in the deployment of TAMECAT, a modular surveillance and collection framework that supports enumeration, discovery, arbitrary command execution, browser credential and cookie collection, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
send it out through several channels, including HTTPS, Discord, and Telegram
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to collect search-ms and WebDAV-related data along with browser credentials and cookies.
A modular surveillance and collection framework supporting enumeration, discovery, arbitrary command execution, browser credential and cookie theft, Outlook .ost mailbox collection, screenshot capture, and fallback C2 and exfiltration mechanisms.
TAMECAT is a multi-function malware used in APT42 phishing campaigns. It is delivered via a WebDAV-hosted LNK/command chain and can collect browser cookies and credentials, search for files, capture screenshots, access Outlook mailbox data, run commands, package stolen information, and exfiltrate data over channels including HTTPS, Discord, and Telegram.
A modular, fileless malware that uses VBScript phishing and PowerShell-based staged delivery, decrypts payloads in memory, steals browser credentials and system information, captures screenshots, receives commands via Telegram bots, and exfiltrates encrypted data through C2 channels including dedicated servers, Discord, and Telegram.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.