Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S1193
malware
TAMECAT
TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 10
uses
T1059.003
Windows Command Shell
uses
T1105
Ingress Tool Transfer
uses
T1059.005
Visual Basic
uses
T1132.001
Standard Encoding
uses
T1047
Windows Management Instrumentation
uses
T1573.001
Symmetric Cryptography
uses
T1518.001
Security Software Discovery
uses
T1059.001
PowerShell
uses
T1071.001
Web Protocols
uses by
G1044
APT42