TAMECAT — Malware Profile
TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.
MITRE ATT&CK techniques (9)
- T1047 Windows Management Instrumentation
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1132.001 Standard Encoding
- T1518.001 Security Software Discovery
- T1573.001 Symmetric Cryptography
IntelFusions coverage
- APT42: Iran's IRGC-Linked Espionage Group Deploys Multi-Persona Phishing and Android Spyware Against Dissidents 2026-02-16
- State hackers now log in instead of dropping malware 2026-08-20