TAMECAT

MITRE ATT&CK: S1193 View on attack.mitre.org

Aliases: TAMECAT

Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-03-03 18:33:47
Profile updated
2026-07-07 13:23:27

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:ir

Context

TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to TAMECAT (S1193). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample bd1f0fb085c486e97d82b6e8acb3977497c59c3ac79f973f96c395e7f0ca97f8 2026-03-03 1

Detection coverage

  • 388 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Visual Basic (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

Reports & references

  • cloud.google.com — Untangling Iran Apt42 Operations (report)
  • malpedia.caad.fkie.fraunhofer.de — Vbs.Tamecat (report)
  • web.archive.org — Spearspecter (report)
  • MITRE ATT&CK — S1193 (report)

External references