Researchers have identified a new malware called Kothamine that uses tailcat, a legitimate tool from the mesh VPN service Tailscale, to receive commands from attackers through an encrypted connection. The use of tailcat eliminates the need for malicious domains for communication, making it harder to block via traditional blacklists.
The discovery was published on the Malwarebytes blog on September 25. The malware operates within a broader trend of abusing legitimate tools to camouflage command-and-control traffic, a technique known as living-off-the-land (LotL). The difference here is that tailcat is not a native operating system utility, but a third-party tool widely used by network administrators.
Tailscale builds mesh networks based on WireGuard, and tailcat is a lightweight client that allows access to internal network resources without manually configuring tunnels. The malware incorporates this functionality to establish a persistent communication channel that blends in with legitimate administrative traffic.
For security teams managing environments that use Tailscale, detecting Kothamine requires going beyond network signatures. Since the traffic is encrypted and uses authorized endpoints, the approach must focus on anomalous tailcat process behavior — such as execution out of context, unusual times, or communication with peers not registered in the organization's policy.
The paper assesses that the Kothamine case reinforces a known but often overlooked principle: legitimate administration tools can be the best hiding place for malware. Blocking tailcat without affecting operations is not viable in environments that depend on Tailscale. The practical solution is to monitor the execution baseline of approved utilities and trigger alerts when behavior deviates from the norm. No tool should be considered inherently safe just because it is legitimate.
