Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome

The PowerShell-based malware known as TAMECAT has been identified as a notable threat to enterprise security, focusing on extracting login credentials from Microsoft Edge and Chrome browsers.

The PowerShell-based malware known as TAMECAT has been identified as a notable threat to enterprise security, focusing on extracting login credentials from Microsoft Edge and Chrome browsers.

TAMECAT is part of espionage activities led by APT42, a cyber-espionage group sponsored by the Iranian state, targeting high-value defense and government officials globally.

The malware features advanced capabilities in credential theft, data exfiltration, and maintaining persistent access to compromised systems.

The infection process begins with social engineering tactics, where attackers impersonate trusted WhatsApp contacts to send malicious links exploiting the search-ms URI protocol handler.

Upon activation, a VBScript is downloaded to perform antivirus detection on the target system, determining the appropriate execution path.

TAMECAT utilizes multiple command-and-control channels, including Telegram bots, Discord, Firebase, and Cloudflare Workers infrastructure, as identified by Pulsedive Threat Research analysts.

The PowerShell-based malware known as TAMECAT has been identified as a notable threat to enterprise security, focusing on extracting login credentials from Microsoft Edge and Chrome browsers.
Omar Sabbagh · The Levant Herald

The malware's modular architecture allows for downloading additional PowerShell scripts and executing remote commands. Modules may focus on browser credential extraction, screen capture, and file system crawling.

WebDAV servers are used to deliver malicious LNK files disguised as PDF documents, which establish persistence through logon scripts and registry run keys when executed.

Communication with command-and-control infrastructure occurs via encrypted channels, employing AES encryption with predefined keys to secure stolen data during transit.

Browser Credential Extraction Mechanism

TAMECAT extracts login credentials from Microsoft Edge and Chrome using sophisticated techniques.

Advertisement

For Microsoft Edge, the remote debugging feature is used to access browser data while running. For Chrome, the browser process is temporarily suspended to access stored credential databases.

The credential extraction module operates entirely in memory, leaving minimal forensic traces.

Once credentials are collected, TAMECAT uses its Download Module and a DLL component called Runs.dll to segment the data before exfiltration, evading network monitoring tools by using multiple channels such as FTP and HTTPS.

TAMECAT represents a significant security challenge due to its advanced techniques and capability to evade detection, emphasizing the need for robust cybersecurity measures.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories