Back to Intelligence

Kothamine RAT, Python MaaS Stealer Factory & ShinyHunters/UNC6240 PeopleSoft Exploitation: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
September 28, 2026
9 min read

Three concurrent OTX pulses published on 2026-09-28 paint a consistent picture: credential theft and data extortion operations are converging on three vectors simultaneously — supply-chain-delivered RATs, commodity MaaS infostealers, and mass exploitation of enterprise ERP platforms. All three are TLP:WHITE and immediately actionable.

Threat Summary

These pulses collectively describe the full lifecycle of modern credential-theft operations:

  1. Initial access via supply chain and mass exploitation. The Kothamine Agent RAT is being distributed through malicious npm packages, targeting developer workstations in the technology sector — a classic pathway to downstream enterprise compromise. In parallel, UNC6240 (ShinyHunters) has resumed mass exploitation of CVE-2026-35273, a critical Oracle PeopleSoft vulnerability, hitting education, technology, healthcare, agriculture, transportation, and government sectors globally.

  2. Evasion as a design principle. Kothamine tunnels its C2 through Tailscale's tailcat utility, blending malicious traffic into legitimate encrypted mesh-VPN flows. UNC6240 bypassed WAF inspection by URL-encoding a single character in the request path to reach the vulnerable Environment Manager component. The Python MaaS stealer ships with anti-VM checks and Nuitka/PyInstaller compilation to defeat static analysis.

  3. Objective: credential harvesting and data extortion. Kothamine variants steal browser data and can record camera/microphone. The Python MaaS builder produces customized Windows infostealers with webhook-based exfiltration. ShinyHunters' PeopleSoft intrusions culminate in data theft followed by extortion — their established monetization model.

The combined picture: initial access brokers and extortion actors are industrializing credential theft at both the developer-workstation and enterprise-application layers.

Threat Actor / Malware Profile

Kothamine Agent (RAT / Stealer)

  • Distribution: Malicious npm packages; targets Windows systems in the technology sector.
  • Payload behavior: Undocumented RAT with 30+ supported commands — command execution, file manipulation, and runtime capability extension. Select variants include browser credential/cookie theft and camera/microphone recording.
  • C2 communication: Abuses Tailscale's tailcat for encrypted C2, making malicious sessions nearly indistinguishable from legitimate Tailscale mesh traffic at the network layer.
  • Anti-analysis: Encrypted C2 channel; living-off-the-land abuse of a signed, legitimate networking tool.

Python-Based MaaS Infostealer Builder ("Stealer Factory")

  • Distribution: Malware-as-a-Service builder sold to operators; generates customized Windows executables.
  • Payload behavior: Browser data extraction, credential theft, webhook-based exfiltration (XOR + Base64 encoded configuration).
  • Evasion: Compiled via Nuitka or PyInstaller; anti-VM checks; automatic dependency installation during build; multiple compilation backends to vary signatures across builds.

UNC6240 / ShinyHunters (Extortion Actor)

  • Initial access: Mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, reaching the Environment Manager via a single-character URL-encoding WAF bypass.
  • Post-exploitation tooling: SIDEEYE backdoor, Neo-reGeorg web shell/proxy, and MeshAgent for persistent remote access.
  • Objective: Bulk data theft from PeopleSoft environments followed by extortion — consistent with ShinyHunters' historical breach-and-leak campaigns.

IOC Analysis

The indicator set spans four types, each requiring distinct operationalization:

  • File hashes (SHA256/MD5): Kothamine Agent payloads, SIDEEYE/Neo-reGeorg/MeshAgent artifacts, and MaaS stealer samples. Push all hashes to EDR blocklists and retro-hunt across endpoint telemetry. MD5 hashes from the MaaS pulse are per-build artifacts — expect high hash turnover; prioritize behavioral detections over hash matching for the builder output.
  • IPv4 104.219.234.138: UNC6240 infrastructure. Block at egress, and retro-search proxy/firewall/NetFlow logs for connections from PeopleSoft servers and DMZ hosts.
  • Domain azurenetfiles.net: Attacker-controlled domain masquerading as Azure infrastructure. Add to DNS sinkhole; hunt DNS query logs. Note the typosquat pattern — alert on similar lookalike registrations.
  • CVE-2026-35273: Treat as an active exploitation signal, not just an IOC. Any internet-facing PeopleSoft instance is presumed targeted. Scan for the vulnerability, and inspect web logs for path requests containing encoded characters targeting the Environment Manager component.

Tooling: hash lookups via your EDR/VirusTotal/MISP; domain/IP enrichment via passive DNS and OTX pulse pivoting; WAF log analysis for single-character URL-encoded paths (e.g., %2f, %2e) in PeopleSoft request URIs.

Detection Engineering

YAML
---
title: Kothamine Agent C2 via Tailscale Tailcat
id: 9c4e2a1b-7d3f-4a5e-9b1c-kothamine001
status: experimental
description: Detects execution of Tailscale tailcat utility by non-standard parent processes or from unusual paths, consistent with Kothamine Agent RAT encrypted C2 abuse.
author: Security Arsenal
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith: '\tailcat.exe'
  selection_suspicious_parent:
    ParentImage|endswith:
      - '\node.exe'
      - '\npm.exe'
      - '\cmd.exe'
      - '\powershell.exe'
      - '\wscript.exe'
      - '\rundll32.exe'
  selection_suspicious_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\ProgramData\'
      - '\Users\Public\'
  condition: selection_img and (selection_suspicious_parent or selection_suspicious_path)
falsepositives:
  - Legitimate Tailscale administrative use by IT teams
level: high
tags:
  - attack.command_and_control
  - attack.t1105
  - attack.t1219
date: 2026/09/28
---
title: Python MaaS Infostealer Browser Credential Access
id: 7b1d3f2a-4c8e-4d2a-8e5b-maasstealer01
status: experimental
description: Detects unsigned or Python-compiled binaries (Nuitka/PyInstaller) accessing browser credential stores such as Chrome Login Data or cookies databases.
author: Security Arsenal
logsource:
  category: file_event
  product: windows
detection:
  selection_target:
    TargetFilename|contains:
      - '\Google\Chrome\User Data\'
      - '\Microsoft\Edge\User Data\'
      - '\BraveSoftware\Brave-Browser\User Data\'
  selection_files:
    TargetFilename|endswith:
      - '\Login Data'
      - '\Cookies'
      - '\Web Data'
      - '\Local State'
  filter_known_browsers:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\brave.exe'
      - '\MsMpEng.exe'
  condition: selection_target and selection_files and not filter_known_browsers
falsepositives:
  - Legitimate backup or password management software
level: high
tags:
  - attack.credential_access
  - attack.t1555.003
date: 2026/09/28
---
title: UNC6240 PeopleSoft Web Shell and Tunneling Tool Deployment
id: 3e8a5c1d-2f6b-4a9c-b7d4-unc6240psoft1
status: experimental
description: Detects web server or Java processes spawning shells, MeshAgent, or proxy tooling consistent with SIDEEYE/Neo-reGeorg deployment following PeopleSoft CVE-2026-35273 exploitation.
author: Security Arsenal
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\java.exe'
      - '\javaw.exe'
      - '\w3wp.exe'
      - '\httpd.exe'
      - '\tomcat9.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\meshagent.exe'
      - '\meshagent64.exe'
      - '\netsh.exe'
      - '\certutil.exe'
  condition: selection_parent and selection_child
falsepositives:
  - PeopleSoft administrative scripts executed by application teams
level: critical
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.t1059
date: 2026/09/28
KQL — Microsoft Sentinel / Defender
// Sentinel hunt: Kothamine tailcat C2, MaaS stealer execution, UNC6240 infrastructure & hashes
let ioc_hashes = dynamic(["ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0","74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c","2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7","3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3","419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86","48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494","ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07","429ed63ab3fbda8d22d0ac750ecfe8cc","610f0c65a3f8e88559f89ed90ea9ee5c","9ffe0e45c7a3f20e4481206c1c3b0854"]);
let ioc_ips = dynamic(["104.219.234.138"]);
let ioc_domains = dynamic(["azurenetfiles.net"]);
union isfuzzy=true
  (DeviceNetworkEvents
   | where TimeGenerated > ago(30d)
   | where RemoteIP in~ (ioc_ips) or RemoteUrl has_any (ioc_domains)
   | project TimeGenerated, DeviceName, ActionType, RemoteIP, RemoteUrl, InitiatingProcessFileName, InitiatingProcessCommandLine, DetectionSource=tostring("Network-IOC")),
  (DeviceProcessEvents
   | where TimeGenerated > ago(30d)
   | where SHA256 in~ (ioc_hashes) or MD5 in~ (ioc_hashes)
   | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, SHA256, MD5, InitiatingProcessFileName, DetectionSource=tostring("Hash-IOC")),
  (DeviceProcessEvents
   | where TimeGenerated > ago(30d)
   | where FileName =~ "tailcat.exe" and InitiatingProcessFileName has_any ("node.exe","npm.exe","cmd.exe","powershell.exe")
   | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, DetectionSource=tostring("Tailcat-Behavior")),
  (DeviceFileEvents
   | where TimeGenerated > ago(30d)
   | where FolderPath has_any ("\\Login Data","\\Cookies","\\Local State") and FolderPath has_any ("Chrome\\User Data","Edge\\User Data")
     and InitiatingProcessFileName !in~ ("chrome.exe","msedge.exe","MsMpEng.exe")
   | project TimeGenerated, DeviceName, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, DetectionSource=tostring("BrowserCredAccess"))
| sort by TimeGenerated desc
PowerShell
# Kothamine / MaaS Stealer / UNC6240 endpoint IOC hunt — run via EDR live response or GPO
$ErrorActionPreference = 'SilentlyContinue'
$Report = @()

# 1) Running/network artifacts: Tailscale tailcat C2 and UNC6240 infrastructure
$conns = Get-NetTCPConnection | Where-Object { $_.RemoteAddress -eq '104.219.234.138' }
foreach ($c in $conns) { $Report += "NETCONN: $($c.LocalAddress):$($c.LocalPort) -> $($c.RemoteAddress):$($c.RemotePort) PID=$($c.OwningProcess)" }

$tailcat = Get-Process | Where-Object { $_.Name -match 'tailcat' }
foreach ($p in $tailcat) { $Report += "PROCESS: tailcat running PID=$($p.Id) Path=$($p.Path)" }

# 2) Unsigned binaries in temp/user-writable paths (Nuitka/PyInstaller MaaS droppers)
$paths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","C:\Users\Public","C:\ProgramData")
foreach ($p in $paths) {
  Get-ChildItem -Path $p -Recurse -Include *.exe -ErrorAction SilentlyContinue | ForEach-Object {
    $sig = Get-AuthenticodeSignature $_.FullName
    if ($sig.Status -ne 'Valid') { $Report += "UNSIGNED-EXE: $($_.FullName) (SHA256: $((Get-FileHash $_.FullName -Algorithm SHA256).Hash))" }
  }
}

# 3) Persistence: Run keys and scheduled tasks referencing suspicious paths
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($k in $runKeys) {
  (Get-ItemProperty $k).PSObject.Properties | Where-Object { $_.Value -match 'Temp|AppData|Public|ProgramData|tailcat|meshagent' } |
    ForEach-Object { $Report += "RUNKEY: $k -> $($_.Name) = $($_.Value)" }
}
Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'Temp|AppData|Public|tailcat|meshagent' } |
  ForEach-Object { $Report += "SCHTASK: $($_.TaskName) -> $($_.Actions.Execute)" }

# 4) MeshAgent service presence (UNC6240 tooling)
$mesh = Get-Service | Where-Object { $_.Name -match 'mesh' }
foreach ($s in $mesh) { $Report += "SERVICE: $($s.Name) Status=$($s.Status)" }

# 5) DNS cache check for attacker domain
$dns = Get-DnsClientCache | Where-Object { $_.Entry -match 'azurenetfiles\.net' }
foreach ($d in $dns) { $Report += "DNSCACHE: $($d.Entry) -> $($d.Data)" }

$Report | Out-File "$env:TEMP\otx_hunt_2026-09-28.txt"
if ($Report.Count -gt 0) { Write-Host "[!] $($Report.Count) findings — see $env:TEMP\otx_hunt_2026-09-28.txt" } else { Write-Host "[+] No IOC artifacts found on this host." }

Response Priorities

Immediate (0–4h)

  • Block 104.219.234.138 and azurenetfiles.net at egress, DNS, and proxy layers; push all 12 file hashes to EDR blocklists.
  • Hunt for tailcat.exe executed by non-Tailscale parents (node/npm/script interpreters) — this is the highest-fidelity Kothamine signal.
  • Inventory internet-facing Oracle PeopleSoft instances; if unpatched against CVE-2026-35273, isolate or take offline until patched. Review WAF logs for single-character URL-encoded path requests against Environment Manager.
  • Audit npm package installs on developer workstations in the last 30 days for anomalous or recently published packages.

24 Hours

  • All three campaigns exfiltrate credentials or data. Force password resets and session token revocation for any user whose endpoint shows browser credential store access by non-browser processes, and for any PeopleSoft service/admin accounts on exploited systems.
  • Revoke and reissue session cookies where browser data theft is suspected — infostealers specifically target session tokens to bypass MFA.
  • Check for unauthorized webhook exfiltration: review outbound HTTPS to Discord/Telegram webhook endpoints from workstations.
  • Verify MFA enrollment on all PeopleSoft administrative and ERP accounts; ShinyHunters leverages stolen credentials for extortion leverage.

1 Week

  • Patch all PeopleSoft instances for CVE-2026-35273; add WAF rules that normalize and decode URL-encoded paths before inspection to close the single-character bypass class.
  • Segment ERP/PeopleSoft servers from general user networks; restrict outbound internet access from application servers to an explicit allowlist.
  • Deploy application control (WDAC/AppLocker) to block unsigned binaries in user-writable directories — this neuters PyInstaller/Nuitka MaaS droppers.
  • Establish detection coverage for legitimate-tool abuse: baseline approved Tailscale/MeshAgent deployments and alert on any instance outside the approved inventory.
  • Implement npm package vetting (lockfile integrity checks, private registry proxying, install-time sandboxing) for developer environments.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.