TAMECAT
MITRE ATT&CK: S1193 View on attack.mitre.org
Aliases: TAMECAT
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-03-03 18:33:47
- Profile updated
- 2026-07-07 13:23:27
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:ir
Context
TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to TAMECAT (S1193). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | bd1f0fb085c486e97d82b6e8acb3977497c59c3ac79f973f96c395e7f0ca97f8 | 2026-03-03 | 1 |
Detection coverage
- 388 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Visual Basic (attack-pattern)
- Standard Encoding (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Security Software Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- APT42 (threat-actor)
Reports & references
- cloud.google.com — Untangling Iran Apt42 Operations (report)
- malpedia.caad.fkie.fraunhofer.de — Vbs.Tamecat (report)
- web.archive.org — Spearspecter (report)
- MITRE ATT&CK — S1193 (report)