TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome
The PowerShell-based malware known as TAMECAT has been identified as a notable threat to enterprise security, focusing on extracting login credentials from Microsoft Edge and Chrome browsers.
The PowerShell-based malware known as TAMECAT has been identified as a notable threat to enterprise security, focusing on extracting login credentials from Microsoft Edge and Chrome browsers.
TAMECAT is part of espionage activities led by APT42, a cyber-espionage group sponsored by the Iranian state, targeting high-value defense and government officials globally.
The malware features advanced capabilities in credential theft, data exfiltration, and maintaining persistent access to compromised systems.
The infection process begins with social engineering tactics, where attackers impersonate trusted WhatsApp contacts to send malicious links exploiting the search-ms URI protocol handler.
Upon activation, a VBScript is downloaded to perform antivirus detection on the target system, determining the appropriate execution path.
TAMECAT utilizes multiple command-and-control channels, including Telegram bots, Discord, Firebase, and Cloudflare Workers infrastructure, as identified by Pulsedive Threat Research analysts.
The PowerShell-based malware known as TAMECAT has been identified as a notable threat to enterprise security, focusing on extracting login credentials from Microsoft Edge and Chrome browsers.
The malware's modular architecture allows for downloading additional PowerShell scripts and executing remote commands. Modules may focus on browser credential extraction, screen capture, and file system crawling.
WebDAV servers are used to deliver malicious LNK files disguised as PDF documents, which establish persistence through logon scripts and registry run keys when executed.
Communication with command-and-control infrastructure occurs via encrypted channels, employing AES encryption with predefined keys to secure stolen data during transit.
Browser Credential Extraction Mechanism
TAMECAT extracts login credentials from Microsoft Edge and Chrome using sophisticated techniques.
For Microsoft Edge, the remote debugging feature is used to access browser data while running. For Chrome, the browser process is temporarily suspended to access stored credential databases.
The credential extraction module operates entirely in memory, leaving minimal forensic traces.
Once credentials are collected, TAMECAT uses its Download Module and a DLL component called Runs.dll to segment the data before exfiltration, evading network monitoring tools by using multiple channels such as FTP and HTTPS.
TAMECAT represents a significant security challenge due to its advanced techniques and capability to evade detection, emphasizing the need for robust cybersecurity measures.
Based on reporting by Cyber Security News.




