A ‘Taj Mahal’ warning for you

Date:

Trending

Researchers with cyber security firm Kaspersky Lab have uncovered a sophisticated spying platform, TajMahal, that has been active for more than five years now and appears to be unconnected to any known threat actors.

- Advertisement -

The TajMahal framework features around 80 malicious modules and includes functionality is never before seen in an advanced persistent threat, such as the ability to steal information from printer queues and to grab previously seen files from a USB device the next time it reconnects, the researchers said.

Kaspersky Lab has so far seen only one victim, a foreign-based central Asian embassy, but it is likely that others have been affected.

- Advertisement -

“It seems highly unlikely that such a huge investment would be undertaken for only one victim. This suggests that there are either further victims not yet identified, or additional versions of this malware in the wild, or possibly both,” said Alexey Shulmin, Lead Malware Analyst at Kaspersky Lab.

“The distribution and infection vectors for the threat also remain unknown. Somehow, it has stayed under the radar for over five years. Whether this is due to relative inactivity or something else is another intriguing question. There are no attribution clues nor any links we can find to known threat groups,” Shulmin added.

The name “TajMahal” comes from the name of the file used to exfiltrate the stolen data, Kaspersky Lab said.

The TajMahal framework is believed to include two main packages, self-named as “Tokyo” and “Yokohama”.

Tokyo is the smaller of the two, with around three modules. It contains the main backdoor functionality, and periodically connects with the command and control servers. Tokyo leverages PowerShell and remains in the network even after the intrusion has moved to stage two.

Stage two is the Yokohama package: a fully armed spying framework. Yokohama includes a Virtual File System (VFS) with all plug-ins, open source and proprietary third-party libraries, and configuration files. There are nearly 80 modules in all, and they include loaders, orchestrators, command and control communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers.

TajMahal is also able to grab browser cookies, gather the backup list for Apple mobile devices, steal data from a CD burnt by a victim as well as documents in a printer queue, the researchers said.

It can also request the theft of a particular file from a previously seen USB stick, and the file will be stolen the next time the USB is connected to the computer.

The targeted systems found by Kaspersky Lab were infected with both Tokyo and Yokohama. This suggests that Tokyo was used as first stage infection, deploying the fully-functional Yokohama package on interesting victims, and then left in for backup purposes.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

12 Eye-Popping Hacks to Make Your Next Business Presentation Sparkle

Business presentations are often necessary to gain new clients and showcase what it is you can offer, but more often than not, they end...

The Long-Term Power of Investing: Selecting Undervalued Industries

Investing can seem overwhelming, especially for beginners, as the numerous options and strategies available can make it easy to feel unsure about where to start. However, one time-tested method that stands out is long-term investing—focusing on companies and industries with the potential for growth...

The Impact of EdTech on Student Outcomes in Higher Education

The introduction of interactive whiteboards in the early 1990s marked a major shift in...

Meta Legal Head Offloads Shares worth $577K

Meta Platforms Inc.’s (NASDAQ: META) Chief Legal Officer, Jennifer Newstead, has sold 921 shares,...

HR Chief Amy Coleman Reports Over 46,000 Microsoft Shares in SEC Filing

Microsoft (NASDAQ: MSFT) Chief Human Resources Officer, Amy Coleman, has reported her stock holdings...

BGC Group raises $700 Mn in bond sale to refinance debt

BGC Group, Inc. (NASDAQ: BGC) has finalized a $700 million private offering of senior...

The Ultimate Guide to Choosing and Using Fonts in Your Design Projects

Fonts play a crucial role in every design project, from branding and web design...

Predictive Analytics: The Key to Supply Chain Resilience

In today’s interconnected global economy, supply chains are the lifeblood of businesses, weaving intricate...

Shell Executive Robin Mooldijk Sells €1.69 Mn in Shares

Shell plc’s Projects & Technology Director, Robin Mooldijk, has offloaded 50,000 shares in the company, amounting to approximately €1.69 million. According to the filing, the...

Empowering Growth: Boosting the Robotics Sector with Targeted Support

India's robotics sector is emerging as a key area of technological progress, driving innovation...

Software and Technology Changing the Industry

The advent of software and technological advancements has been a game-changer across various industries....

RP-Sanjiv Goenka’s Firstsource Opens ANZ HQ and AI Lab in Melbourne

Firstsource Solutions Limited (NSE: FSL, BSE:532809), an RP-Sanjiv Goenka Group company, today announced the...
00:02:53

Canada, Australia Partner to Build $6 Bn Arctic Radar System

In a bid to enhance Arctic and national security, Canada's Prime Minister Mark Carney...

Meta Chief Legal Officer Jennifer Newstead Offloads Shares as Part of Trading Plan

According to regulatory filings, Jennifer Newstead, Chief Legal Officer at Meta Platforms, Inc. (NASDAQ: META), has divested 921 shares of the company’s Class A...

Nvidia Director Aarti Shah to Sell Shares Worth $2.37 Mn

Aarti S. Shah, a director at NVIDIA Corporation (NASDAQ: NVDA), has filed a notice with the Securities and Exchange Commission (SEC) to sell 20,000 shares of the company’s common stock under Rule 144. According to the Form 144 filing, submitted on March 20, 2025, Shah...

Alphabet Board Member Frances Arnold Increases Stake Following Dividend Allocation

According to a recent regulatory filing, Frances Arnold, a board member at Alphabet Inc.,...

Alphabet COA Amie Thuener O’Toole Increases Stock Holdings

In a filing with the U.S. Securities and Exchange Commission (SEC), Alphabet Inc.’s (NASDAQ...

Google Acquires Wiz for $32 Billion in All-Cash Deal

Google LLC, a subsidiary of Alphabet Inc. (NASDAQ: GOOG, GOOGL) has signed a deal...

The Sustainability Imperative: How IT Distribution Is Driving Green Tech Adoption

In today's day and time sustainability is no longer just a corporate commitment, it...

The Future of Digital Payments and Cybersecurity Challenges

The future of digital payments is evolving rapidly, driven by technological advancements, changes in...

How a Money Back Policy Can Be a Smart Financial Choice?

Creating financial security involves strategic planning because investment decisions form one of the essential...

From Startup to Success: Essential Steps for Landscaping Entrepreneurs

Starting a landscaping business is so exciting, blending creativity with the reward of transforming...
00:02:23

‘Canada Ripping Us’: US President Trump Criticizes High Tariffs on Dairy and Lumber

U.S. President Donald Trump on Friday slammed Canada’s high tariffs on American dairy and...

Trade War: Canadian PM Justin Trudeau Announces 25% Tariffs On US Imports

Ottawa: Canadian Prime Minister Justin Trudeau on Wednesday announced a 25% tariff on U.S....

RP-Sanjiv Goenka’s Firstsource Opens ANZ HQ and AI Lab in Melbourne

Firstsource Solutions Limited (NSE: FSL, BSE:532809), an RP-Sanjiv Goenka Group company, today announced the...

Elon Musk’s X Sues Indian Govt Over Content Regulation Clash

X Corp, an Elon Musk-owned social media firm, sued the Indian government in the...

Why Smart Cities Are the Future of Water Conservation

Water conservation has become an important factor due to climate change and worsened water...

Alphabet CEO Sundar Pichai Increases Stocks Holdings Amid Dividend Adjustment

According to a regulatory filing with the U.S. Securities and Exchange Commission (SEC), Alphabet...

Layer PR Wins SME News UK Awards, Expands to Bengaluru

Layer PR, a global public relations firm owned by TechGraph, has secured two major...
00:02:53

Canada, Australia Partner to Build $6 Bn Arctic Radar System

In a bid to enhance Arctic and national security, Canada's Prime Minister Mark Carney...

‘Canada Ripping Us’: US President Trump Criticizes High Tariffs on Dairy and Lumber

U.S. President Donald Trump on Friday slammed Canada’s high tariffs on American dairy and...

Trump Defends Elon Musk Plan for Federal Job Cuts; Govt Spending ‘Bloated’

Following a meeting with Elon Musk and senior cabinet members, U.S. President Donald Trump...

Trade War: Canadian PM Justin Trudeau Announces 25% Tariffs On US Imports

Ottawa: Canadian Prime Minister Justin Trudeau on Wednesday announced a 25% tariff on U.S....