TajMahal

MITRE ATT&CK: S0467 View on attack.mitre.org

Aliases: TajMahal

First seen
2014-01-01 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-06-08 09:39:18
Profile updated
2026-07-07 14:52:14

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

TajMahal is a multifunctional spying framework that has been in use since at least 2014. TajMahal is comprised of two separate packages, named Tokyo and Yokohama, and can deploy up to 80 plugins.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to TajMahal (S0467). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample f585646456_b64_decoded_exe 2026-06-08 1

Detection coverage

  • 310 Sigma rules

Malware & tools used

  • Archive via Library (attack-pattern)
  • Video Capture (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • Audio Capture (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Process Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Shared Modules (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Data from Removable Media (attack-pattern)
  • Data from Local System (attack-pattern)
  • Keylogging (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Reports & references

  • Kaspersky — 90240 (report)
  • MITRE ATT&CK — S0467 (report)

External references