A ‘Taj Mahal’ warning for you

Date:

Trending

- Advertisement -

Researchers with cyber security firm Kaspersky Lab have uncovered a sophisticated spying platform, TajMahal, that has been active for more than five years now and appears to be unconnected to any known threat actors.

The TajMahal framework features around 80 malicious modules and includes functionality is never before seen in an advanced persistent threat, such as the ability to steal information from printer queues and to grab previously seen files from a USB device the next time it reconnects, the researchers said.

- Advertisement -

Kaspersky Lab has so far seen only one victim, a foreign-based central Asian embassy, but it is likely that others have been affected.

- Advertisement -

“It seems highly unlikely that such a huge investment would be undertaken for only one victim. This suggests that there are either further victims not yet identified, or additional versions of this malware in the wild, or possibly both,” said Alexey Shulmin, Lead Malware Analyst at Kaspersky Lab.

“The distribution and infection vectors for the threat also remain unknown. Somehow, it has stayed under the radar for over five years. Whether this is due to relative inactivity or something else is another intriguing question. There are no attribution clues nor any links we can find to known threat groups,” Shulmin added.

- Advertisement -

The name “TajMahal” comes from the name of the file used to exfiltrate the stolen data, Kaspersky Lab said.

The TajMahal framework is believed to include two main packages, self-named as “Tokyo” and “Yokohama”.

Tokyo is the smaller of the two, with around three modules. It contains the main backdoor functionality, and periodically connects with the command and control servers. Tokyo leverages PowerShell and remains in the network even after the intrusion has moved to stage two.

Stage two is the Yokohama package: a fully armed spying framework. Yokohama includes a Virtual File System (VFS) with all plug-ins, open source and proprietary third-party libraries, and configuration files. There are nearly 80 modules in all, and they include loaders, orchestrators, command and control communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers.

TajMahal is also able to grab browser cookies, gather the backup list for Apple mobile devices, steal data from a CD burnt by a victim as well as documents in a printer queue, the researchers said.

It can also request the theft of a particular file from a previously seen USB stick, and the file will be stolen the next time the USB is connected to the computer.

The targeted systems found by Kaspersky Lab were infected with both Tokyo and Yokohama. This suggests that Tokyo was used as first stage infection, deploying the fully-functional Yokohama package on interesting victims, and then left in for backup purposes.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -
Krishna Mali
Krishna Mali
Founder & Group Editor of TechGraph.

More Latest Stories

More Articles

How to Extend Vehicle Lifespan With Proper Maintenance

Extending the lifespan of your vehicle is not only cost-effective but also beneficial for the environment. Proper auto maintenance can significantly contribute to how...

Geospatial Intelligence Is Powering India’s Next Wave of Smart Infrastructure

Every day, nearly 500 families in India receive news that will change their lives forever: a loved one lost to a road accident. In 2024 alone, approximately 180,000 people died on Indian roads, according to Union Minister Nitin Gadkari. Among them were 10,000 school...

Understanding Common Car Problems and How to Prevent Them

Keeping your vehicle in top condition requires more than just regular washing or occasional...

From Browsing to Buying: How Multi-Modal AI Is Turning Discovery Into Decision-Making

The digital journey, starting from discovery to decision, has been notably discontinuous through time....

From vineyard to bottle: How blockchain improves trust and sensing in the wine value chain

The wine sector faces increasing consumer demand for transparency, authenticity, and reliable information about...

Why India’s Next Cloud Boom Is Coming from Tier-2 Cities

Historically, the story of India's cloud adoption has been focused on the metro cities...

Fraud or Finance? How to Identify Trustworthy Digital Lending Platforms

Digital lending has changed how credit flows in India. According to the IBEF, fintech-led...

What Modern Enterprises Can Expect from CPaaS Platforms in 2026

Over the past two decades, enterprise communication technology has advanced rapidly. Yet the gap...

Nebius Gets Approval for 1.2 GW AI Factory Campus in Missouri

Nasdaq-listed AI company, Nebius (NBIS), said the Independence City Council has approved a Chapter 100 industrial development incentive plan for its planned AI factory...

Choosing glass for perfume bottles? Watch for breakage and leaks

You want your perfume bottle to look great and arrive safely. That’s easiest when...

How To Use Tech To Aid Your Financial Management

Financial management and tech actually go hand in hand really well, and it’s important...

What Budget 2026 Should Do for Responsible AI Adoption

Over the past 5 years, Artificial Intelligence (AI) has become a core component of...

Creator Commerce Platform Wishlink Secures $17.5 Mn in Series B round

India-based creator commerce platform Wishlink has raised $17.5 million in a Series B funding...

Brazil and South Korea Sign Stragetic Deals Across Trade, Health & Tech

In a move aimed at strengthening economic and strategic ties, Brazilian President Luiz Inácio Lula da Silva and South Korean President Lee Jae Myung...

Amazon India Opens 1.1 Million Sq Ft Campus in Bengaluru

Amazon announced the opening of its second-largest office in Asia with the launch of a 1.1 million square feet, 12-storey campus in Bengaluru (Karnataka) that will support more than 7,000 employees across ecommerce, operations, payments, technology, and seller services in India. The facility has been...

B2B Logistics platform Mojro Draws $3Mn for IAN Alpha Fund & Others

Bengaluru-based B2B logistics platform Mojro has raised $3 million in a Series A funding...

Peak XV Partners Closes $1.3 Bn in Fresh Capital to Back Startups Across India and APAC

Peak XV Partners (formerly Sequoia Capital India & SEA) has closed $1.3 billion in...

Union Budget Focus on MSMEs: Why Efficient Warehousing Is the Missing Link

The Union Budget 2026–27 places Micro, Small, and Medium Enterprises (MSMEs) firmly at the...

Union Budget 2026: Solar & Clean Energy Industry Draws Mixed Reactions on Manufacturing, KUSUM Funding & Import Duty Exemptions

The solar and clean energy sector has welcomed Union Budget 2026–27 for its focus...

Union Budget 2026 Reactions: AI, Skilling Take Centre Stage, Education Sector Calls for Better Execution

The education and skilling sector has broadly welcomed the Union Budget 2026 for its...

Union Budget 2026 Reactions: Healthcare Sector Welcomes Biopharma and Infra Push, Calls Public Health Investment Modest

The healthcare and healthtech sector welcomed the Union Budget 2026 for its focus on...

Union Budget 2026: Nirmala Sitharaman Raises Capex to ₹12.2 Lakh Crore, Fiscal Deficit Projected at 4.3% for FY27

Union Budget 2026: Finance Minister Nirmala Sitharaman said the government has allocated ₹12.2 lakh...

Why India’s Housing Affordability Crisis Needs Policy Attention in Budget 2026

In the past few years, real estate prices have risen steadily, especially in tier-one...

India’s Tech Sector Looks to Budget 2026 for AI Incentives, Cybersecurity & Broader Digital Economy Reforms

As policymakers finalise Budget 2026, leaders across artificial intelligence, quantum computing, spacetech, and semiconductor...

What Budget 2026 Should Do for Responsible AI Adoption

Over the past 5 years, Artificial Intelligence (AI) has become a core component of...

Inflection Point Ventures leads INR 4 Cr seed round in Fintech Startup Roopya

West Bengal based no-code ‘lending-as-a-service’ platform Roopya has raised INR 4 Crore in a...

LTM partners with the Indian Institute of Creative Technologies to strengthen creative technology skilling

LTM, a Larsen & Toubro Group company, and the Indian Institute of Creative Technologies...

How Drone and LiDAR Surveys are Redefining Railway and Highway Project Execution

India’s railway and highway networks rank among the largest and most transformative infrastructure systems...

How Union Budget 2026–27 Supports Small Logistics Players through TReDS and the SME Growth Fund

Union Budget 2026–27 marks a decisive shift in how India supports its small logistics...

Creator Commerce Platform Wishlink Secures $17.5 Mn in Series B round

India-based creator commerce platform Wishlink has raised $17.5 million in a Series B funding...

Why India’s Housing Affordability Crisis Needs Policy Attention in Budget 2026

In the past few years, real estate prices have risen steadily, especially in tier-one...

India’s Creator Economy Seeks Tax Clarity and Social Security Support in Budget 2026

As policymakers finalise Budget 2026, the creator economy stands at a crossroads between rapid...

India’s Tech Sector Looks to Budget 2026 for AI Incentives, Cybersecurity & Broader Digital Economy Reforms

As policymakers finalise Budget 2026, leaders across artificial intelligence, quantum computing, spacetech, and semiconductor...