Three concurrent OTX pulses published on 2026-09-28 paint a consistent picture: credential theft and data extortion operations are converging on three vectors simultaneously — supply-chain-delivered RATs, commodity MaaS infostealers, and mass exploitation of enterprise ERP platforms. All three are TLP:WHITE and immediately actionable.
Threat Summary
These pulses collectively describe the full lifecycle of modern credential-theft operations:
-
Initial access via supply chain and mass exploitation. The Kothamine Agent RAT is being distributed through malicious npm packages, targeting developer workstations in the technology sector — a classic pathway to downstream enterprise compromise. In parallel, UNC6240 (ShinyHunters) has resumed mass exploitation of CVE-2026-35273, a critical Oracle PeopleSoft vulnerability, hitting education, technology, healthcare, agriculture, transportation, and government sectors globally.
-
Evasion as a design principle. Kothamine tunnels its C2 through Tailscale's tailcat utility, blending malicious traffic into legitimate encrypted mesh-VPN flows. UNC6240 bypassed WAF inspection by URL-encoding a single character in the request path to reach the vulnerable Environment Manager component. The Python MaaS stealer ships with anti-VM checks and Nuitka/PyInstaller compilation to defeat static analysis.
-
Objective: credential harvesting and data extortion. Kothamine variants steal browser data and can record camera/microphone. The Python MaaS builder produces customized Windows infostealers with webhook-based exfiltration. ShinyHunters' PeopleSoft intrusions culminate in data theft followed by extortion — their established monetization model.
The combined picture: initial access brokers and extortion actors are industrializing credential theft at both the developer-workstation and enterprise-application layers.
Threat Actor / Malware Profile
Kothamine Agent (RAT / Stealer)
- Distribution: Malicious npm packages; targets Windows systems in the technology sector.
- Payload behavior: Undocumented RAT with 30+ supported commands — command execution, file manipulation, and runtime capability extension. Select variants include browser credential/cookie theft and camera/microphone recording.
- C2 communication: Abuses Tailscale's tailcat for encrypted C2, making malicious sessions nearly indistinguishable from legitimate Tailscale mesh traffic at the network layer.
- Anti-analysis: Encrypted C2 channel; living-off-the-land abuse of a signed, legitimate networking tool.
Python-Based MaaS Infostealer Builder ("Stealer Factory")
- Distribution: Malware-as-a-Service builder sold to operators; generates customized Windows executables.
- Payload behavior: Browser data extraction, credential theft, webhook-based exfiltration (XOR + Base64 encoded configuration).
- Evasion: Compiled via Nuitka or PyInstaller; anti-VM checks; automatic dependency installation during build; multiple compilation backends to vary signatures across builds.
UNC6240 / ShinyHunters (Extortion Actor)
- Initial access: Mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, reaching the Environment Manager via a single-character URL-encoding WAF bypass.
- Post-exploitation tooling: SIDEEYE backdoor, Neo-reGeorg web shell/proxy, and MeshAgent for persistent remote access.
- Objective: Bulk data theft from PeopleSoft environments followed by extortion — consistent with ShinyHunters' historical breach-and-leak campaigns.
IOC Analysis
The indicator set spans four types, each requiring distinct operationalization:
- File hashes (SHA256/MD5): Kothamine Agent payloads, SIDEEYE/Neo-reGeorg/MeshAgent artifacts, and MaaS stealer samples. Push all hashes to EDR blocklists and retro-hunt across endpoint telemetry. MD5 hashes from the MaaS pulse are per-build artifacts — expect high hash turnover; prioritize behavioral detections over hash matching for the builder output.
- IPv4
104.219.234.138: UNC6240 infrastructure. Block at egress, and retro-search proxy/firewall/NetFlow logs for connections from PeopleSoft servers and DMZ hosts. - Domain
azurenetfiles.net: Attacker-controlled domain masquerading as Azure infrastructure. Add to DNS sinkhole; hunt DNS query logs. Note the typosquat pattern — alert on similar lookalike registrations. - CVE-2026-35273: Treat as an active exploitation signal, not just an IOC. Any internet-facing PeopleSoft instance is presumed targeted. Scan for the vulnerability, and inspect web logs for path requests containing encoded characters targeting the Environment Manager component.
Tooling: hash lookups via your EDR/VirusTotal/MISP; domain/IP enrichment via passive DNS and OTX pulse pivoting; WAF log analysis for single-character URL-encoded paths (e.g., %2f, %2e) in PeopleSoft request URIs.
Detection Engineering
---
title: Kothamine Agent C2 via Tailscale Tailcat
id: 9c4e2a1b-7d3f-4a5e-9b1c-kothamine001
status: experimental
description: Detects execution of Tailscale tailcat utility by non-standard parent processes or from unusual paths, consistent with Kothamine Agent RAT encrypted C2 abuse.
author: Security Arsenal
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith: '\tailcat.exe'
selection_suspicious_parent:
ParentImage|endswith:
- '\node.exe'
- '\npm.exe'
- '\cmd.exe'
- '\powershell.exe'
- '\wscript.exe'
- '\rundll32.exe'
selection_suspicious_path:
Image|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\ProgramData\'
- '\Users\Public\'
condition: selection_img and (selection_suspicious_parent or selection_suspicious_path)
falsepositives:
- Legitimate Tailscale administrative use by IT teams
level: high
tags:
- attack.command_and_control
- attack.t1105
- attack.t1219
date: 2026/09/28
---
title: Python MaaS Infostealer Browser Credential Access
id: 7b1d3f2a-4c8e-4d2a-8e5b-maasstealer01
status: experimental
description: Detects unsigned or Python-compiled binaries (Nuitka/PyInstaller) accessing browser credential stores such as Chrome Login Data or cookies databases.
author: Security Arsenal
logsource:
category: file_event
product: windows
detection:
selection_target:
TargetFilename|contains:
- '\Google\Chrome\User Data\'
- '\Microsoft\Edge\User Data\'
- '\BraveSoftware\Brave-Browser\User Data\'
selection_files:
TargetFilename|endswith:
- '\Login Data'
- '\Cookies'
- '\Web Data'
- '\Local State'
filter_known_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\brave.exe'
- '\MsMpEng.exe'
condition: selection_target and selection_files and not filter_known_browsers
falsepositives:
- Legitimate backup or password management software
level: high
tags:
- attack.credential_access
- attack.t1555.003
date: 2026/09/28
---
title: UNC6240 PeopleSoft Web Shell and Tunneling Tool Deployment
id: 3e8a5c1d-2f6b-4a9c-b7d4-unc6240psoft1
status: experimental
description: Detects web server or Java processes spawning shells, MeshAgent, or proxy tooling consistent with SIDEEYE/Neo-reGeorg deployment following PeopleSoft CVE-2026-35273 exploitation.
author: Security Arsenal
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\java.exe'
- '\javaw.exe'
- '\w3wp.exe'
- '\httpd.exe'
- '\tomcat9.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\meshagent.exe'
- '\meshagent64.exe'
- '\netsh.exe'
- '\certutil.exe'
condition: selection_parent and selection_child
falsepositives:
- PeopleSoft administrative scripts executed by application teams
level: critical
tags:
- attack.persistence
- attack.t1505.003
- attack.t1059
date: 2026/09/28
// Sentinel hunt: Kothamine tailcat C2, MaaS stealer execution, UNC6240 infrastructure & hashes
let ioc_hashes = dynamic(["ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0","74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c","2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7","3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3","419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86","48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494","ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07","429ed63ab3fbda8d22d0ac750ecfe8cc","610f0c65a3f8e88559f89ed90ea9ee5c","9ffe0e45c7a3f20e4481206c1c3b0854"]);
let ioc_ips = dynamic(["104.219.234.138"]);
let ioc_domains = dynamic(["azurenetfiles.net"]);
union isfuzzy=true
(DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteIP in~ (ioc_ips) or RemoteUrl has_any (ioc_domains)
| project TimeGenerated, DeviceName, ActionType, RemoteIP, RemoteUrl, InitiatingProcessFileName, InitiatingProcessCommandLine, DetectionSource=tostring("Network-IOC")),
(DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where SHA256 in~ (ioc_hashes) or MD5 in~ (ioc_hashes)
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, SHA256, MD5, InitiatingProcessFileName, DetectionSource=tostring("Hash-IOC")),
(DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName =~ "tailcat.exe" and InitiatingProcessFileName has_any ("node.exe","npm.exe","cmd.exe","powershell.exe")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, DetectionSource=tostring("Tailcat-Behavior")),
(DeviceFileEvents
| where TimeGenerated > ago(30d)
| where FolderPath has_any ("\\Login Data","\\Cookies","\\Local State") and FolderPath has_any ("Chrome\\User Data","Edge\\User Data")
and InitiatingProcessFileName !in~ ("chrome.exe","msedge.exe","MsMpEng.exe")
| project TimeGenerated, DeviceName, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, DetectionSource=tostring("BrowserCredAccess"))
| sort by TimeGenerated desc
# Kothamine / MaaS Stealer / UNC6240 endpoint IOC hunt — run via EDR live response or GPO
$ErrorActionPreference = 'SilentlyContinue'
$Report = @()
# 1) Running/network artifacts: Tailscale tailcat C2 and UNC6240 infrastructure
$conns = Get-NetTCPConnection | Where-Object { $_.RemoteAddress -eq '104.219.234.138' }
foreach ($c in $conns) { $Report += "NETCONN: $($c.LocalAddress):$($c.LocalPort) -> $($c.RemoteAddress):$($c.RemotePort) PID=$($c.OwningProcess)" }
$tailcat = Get-Process | Where-Object { $_.Name -match 'tailcat' }
foreach ($p in $tailcat) { $Report += "PROCESS: tailcat running PID=$($p.Id) Path=$($p.Path)" }
# 2) Unsigned binaries in temp/user-writable paths (Nuitka/PyInstaller MaaS droppers)
$paths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","C:\Users\Public","C:\ProgramData")
foreach ($p in $paths) {
Get-ChildItem -Path $p -Recurse -Include *.exe -ErrorAction SilentlyContinue | ForEach-Object {
$sig = Get-AuthenticodeSignature $_.FullName
if ($sig.Status -ne 'Valid') { $Report += "UNSIGNED-EXE: $($_.FullName) (SHA256: $((Get-FileHash $_.FullName -Algorithm SHA256).Hash))" }
}
}
# 3) Persistence: Run keys and scheduled tasks referencing suspicious paths
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($k in $runKeys) {
(Get-ItemProperty $k).PSObject.Properties | Where-Object { $_.Value -match 'Temp|AppData|Public|ProgramData|tailcat|meshagent' } |
ForEach-Object { $Report += "RUNKEY: $k -> $($_.Name) = $($_.Value)" }
}
Get-ScheduledTask | Where-Object { $_.Actions.Execute -match 'Temp|AppData|Public|tailcat|meshagent' } |
ForEach-Object { $Report += "SCHTASK: $($_.TaskName) -> $($_.Actions.Execute)" }
# 4) MeshAgent service presence (UNC6240 tooling)
$mesh = Get-Service | Where-Object { $_.Name -match 'mesh' }
foreach ($s in $mesh) { $Report += "SERVICE: $($s.Name) Status=$($s.Status)" }
# 5) DNS cache check for attacker domain
$dns = Get-DnsClientCache | Where-Object { $_.Entry -match 'azurenetfiles\.net' }
foreach ($d in $dns) { $Report += "DNSCACHE: $($d.Entry) -> $($d.Data)" }
$Report | Out-File "$env:TEMP\otx_hunt_2026-09-28.txt"
if ($Report.Count -gt 0) { Write-Host "[!] $($Report.Count) findings — see $env:TEMP\otx_hunt_2026-09-28.txt" } else { Write-Host "[+] No IOC artifacts found on this host." }
Response Priorities
Immediate (0–4h)
- Block
104.219.234.138andazurenetfiles.netat egress, DNS, and proxy layers; push all 12 file hashes to EDR blocklists. - Hunt for
tailcat.exeexecuted by non-Tailscale parents (node/npm/script interpreters) — this is the highest-fidelity Kothamine signal. - Inventory internet-facing Oracle PeopleSoft instances; if unpatched against CVE-2026-35273, isolate or take offline until patched. Review WAF logs for single-character URL-encoded path requests against Environment Manager.
- Audit npm package installs on developer workstations in the last 30 days for anomalous or recently published packages.
24 Hours
- All three campaigns exfiltrate credentials or data. Force password resets and session token revocation for any user whose endpoint shows browser credential store access by non-browser processes, and for any PeopleSoft service/admin accounts on exploited systems.
- Revoke and reissue session cookies where browser data theft is suspected — infostealers specifically target session tokens to bypass MFA.
- Check for unauthorized webhook exfiltration: review outbound HTTPS to Discord/Telegram webhook endpoints from workstations.
- Verify MFA enrollment on all PeopleSoft administrative and ERP accounts; ShinyHunters leverages stolen credentials for extortion leverage.
1 Week
- Patch all PeopleSoft instances for CVE-2026-35273; add WAF rules that normalize and decode URL-encoded paths before inspection to close the single-character bypass class.
- Segment ERP/PeopleSoft servers from general user networks; restrict outbound internet access from application servers to an explicit allowlist.
- Deploy application control (WDAC/AppLocker) to block unsigned binaries in user-writable directories — this neuters PyInstaller/Nuitka MaaS droppers.
- Establish detection coverage for legitimate-tool abuse: baseline approved Tailscale/MeshAgent deployments and alert on any instance outside the approved inventory.
- Implement npm package vetting (lockfile integrity checks, private registry proxying, install-time sandboxing) for developer environments.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.