TAMECAT

S1193

Malware.View on attack.mitre.org

About this malware

TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1047
Windows Management Instrumentation

TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1059.001
PowerShell

TAMECAT has used PowerShell to download and run additional content.

T1059.003
Windows Command Shell

TAMECAT has used `cmd.exe` to run the `curl` command.

T1059.005
Visual Basic

TAMECAT has used VBScript to query anti-virus products.

T1071.001
Web Protocols

TAMECAT has used HTTP for C2 communications.

T1105
Ingress Tool Transfer

TAMECAT has used `wget` and `curl` to download additional content.

T1132.001
Standard Encoding

TAMECAT has encoded C2 traffic with Base64.

T1518.001
Security Software Discovery

TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1573.001
Symmetric Cryptography

TAMECAT has used AES to encrypt C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant APT42-untangling Open source
    Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.