TajMahal
MITRE ATT&CK: S0467 View on attack.mitre.org
Aliases: TajMahal
- First seen
- 2014-01-01 00:00:00
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-06-08 09:39:18
- Profile updated
- 2026-07-07 14:52:14
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
TajMahal is a multifunctional spying framework that has been in use since at least 2014. TajMahal is comprised of two separate packages, named Tokyo and Yokohama, and can deploy up to 80 plugins.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to TajMahal (S0467). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | f585646456_b64_decoded_exe | 2026-06-08 | 1 |
Detection coverage
- 310 Sigma rules
Malware & tools used
- Archive via Library (attack-pattern)
- Video Capture (attack-pattern)
- System Information Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- Audio Capture (attack-pattern)
- Security Software Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- System Time Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Process Discovery (attack-pattern)
- Software Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Shared Modules (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Data from Removable Media (attack-pattern)
- Data from Local System (attack-pattern)
- Keylogging (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Clipboard Data (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
Reports & references
- Kaspersky — 90240 (report)
- MITRE ATT&CK — S0467 (report)