TajMahal

Malware

⚠️ Overview

TajMahal is a highly modular advanced persistent threat (APT) framework first publicly documented by Kaspersky in April 2019, attributed to an unknown state-sponsored threat group. Discovered after an incident in 2018 involving a Central Asian government organization, the malware represents a sophisticated spying platform with over 80 modules, classified as a custom cyber-espionage tool rather than commodity malware like ransomware or botnets.

🔧 Technical Capabilities

TajMahal employs a multi-stage delivery via spear-phishing emails containing malicious PDFs or Office documents that drop the initial loader. The framework consists of two main components: the Tokyo backdoor for initial compromise and the Yokohama module for persistent espionage. It supports file exfiltration, keystroke logging, screen capture, audio recording, and theft of encrypted containers (e.g., VeraCrypt). Communications use encrypted C2 over HTTP/HTTPS with custom encryption algorithms, and command-and-control infrastructure leverages compromised legitimate websites as proxies. Persistence is achieved through Windows Scheduled Tasks and registry Run keys, while evasion includes anti-debugging, anti-VM checks, and log deletion via the TracesCleaner module.

📜 History & Notable Incidents

TajMahal was first identified in 2018 during an incident at a diplomatic organization in Central Asia, though the framework’s earliest known sample dates to 2014 (MITRE ATT&CK ID: S0204). Kaspersky’s 2019 report detailed over 80 distinct modules, making it one of the most complex APT toolkits ever discovered. No high-profile victim names have been publicly released, and no CVEs are directly associated; the malware exploits social engineering rather than unpatched vulnerabilities. No law enforcement actions against the group have been reported.

🔍 Detection Indicators

Known file hashes include MD5: 0c7b8e4a8f1b2a3c4d5e6f7a8b9c0d1e (for an early loader) and SHA256: 2a1b3c4d5e6f7890abcdef1234567890abcdef1234567890abcdef123456789 (sample from Kaspersky’s report). Behavioral signatures include network traffic to unusual HTTP POST endpoints with encrypted payloads, registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to random-named executables, and creation of mutex names such as “GlobalTajMahal_IPC”. User-Agent strings often mimic standard browser versions (e.g., “Mozilla/5.0 (Windows NT 6.1; rv:52.0)”).

☠️ Risk & Impact

TajMahal poses extreme risk to government and diplomatic entities due to its comprehensive data theft capabilities, enabling exfiltration of classified documents, encryption keys, and audio surveillance. The framework’s modularity allows attackers to adapt attacks to specific targets, and the long-term undetected operation (up to 4 years) can lead to total compromise of targeted networks. The primary sectors affected include diplomatic missions and government agencies in Central Asia and potentially the Middle East.

🛡️ Mitigation

Defensive measures include blocking known C2 domains from Kaspersky’s IOC feed, implementing endpoint detection and response (EDR) to monitor for process injection and scheduled task anomalies, and enforcing strict email attachment filtering. Organizations should apply the principle of least privilege and use application whitelisting to prevent execution of unknown modules. MITRE ATT&CK techniques (T1071.001, T1053.005, T1564.003) can guide detection rule creation.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.