Kaspersky Announced A TajMahal Warning
Saanvi Araav - Apr 18, 2019
Kaspersky Lab warned us about a spying framework called TajMahal
- Kaspersky Goes Full Plot Twist: From Virus Hunter to SIM Card Dealer
- How 30 Lines Of Code Destroy A 27-Ton Generator
- If You Want To Be Safe, Please Stay Away From These Fake Coronavirus Websites
News coming from New Delhi, a group of researchers at the lab of the cybersecurity firm - Kaspersky has found our a sophisticated spying platform which comes with the name TajMahal. In fact, it has been active for more than five years and seems like there is no connection to other known threat actors. The main framework of TajMahal also has up to 80 malicious modules which include some rather unique functionality, for example, the ability to steal from the printer queues.
There is also the function to grab previously seen files on flash drive devices. On the other hand, this framework is also capable of gathering Apple devices back up list, grab cookies of the browsers, and take data from CD burning.
The victim
The group at Kaspersky Lab has only found one victim of this platform so far, which is a central Asian embassy based in a foreign country. But it is very likely that there were other victims too.

The Lead Malware Analyst at Kaspersky Lab, Alexey Shulmin said that much investment could not be for just one victim, so there might be more which had fallen under its threat that we did not know of or there were other versions, or maybe both. He had not found out about the way it distributed or infected. The platform was able to remain unknown for over five years, which might be the result of its inactivity.
"Yokohama" and "Tokyo."
They added that they named this platform "TajMahal" because that is the name of the file used to exfiltrate the data. In "TajMahal" framework, there are also two main packages "Yokohama" and "Tokyo."

The targeted system of the central Asian embassy we mentioned above was infected with Yokohama and Tokyo. Kaspersky Lab said that Tokyo might be used in the first stage of the operation. While, later on, they used Yokohama to target the real targets.
Featured Stories
ICT News - Feb 10, 2026
Discord's Teen Safety Sham: Why This Data Leak Magnet Isn't Worth Your Trust...
ICT News - Feb 09, 2026
PS6 Rumors: Game-Changing Specs Poised to Transform Console Play
ICT News - Feb 08, 2026
Is Elon Musk on the Path to Becoming the World's First Trillionaire?
ICT News - Feb 07, 2026
NVIDIA's Gaming GPU Drought: No New Releases in 2026 as AI Takes Priority
ICT News - Feb 06, 2026
Elon Musk Clarifies: No Starlink Phone in Development at SpaceX
ICT News - Feb 03, 2026
Elon Musk's SpaceX Acquires xAI in Landmark $1.25 Trillion Merger
ICT News - Feb 02, 2026
Google's Project Genie: Premium Subscribers Unlock Interactive AI-Generated Realms
ICT News - Dec 25, 2025
The Visibility Concentration Effect: Why Half the Web Isn’t Qualified Anymore
ICT News - Jul 05, 2025
Windows 11 is Now the Most Popular Desktop OS in the World
ICT News - Jul 02, 2025
All About Florida’s Alligator Alcatraz: A Smart Move for Immigration Control
Read more
Mobile- Feb 11, 2026
Top 5 Cheap and Efficient Gaming Phones in 2026
These phones prove you don't need $1000+ for efficient gaming. The RedMagic 11 Air leads for pure power, while POCO options win on value.
Mobile- Feb 12, 2026
What is the Most Powerful Gaming Phone Currently?
The Nubia Red Magic 11 Pro is the undisputed most powerful gaming phone right now, blending record-breaking benchmarks, unbeatable cooling, and gamer-centric design for peak performance that lasts.
ICT News- Feb 10, 2026
Discord's Teen Safety Sham: Why This Data Leak Magnet Isn't Worth Your Trust Anymore
Cancel your Nitro, export your data, and move on before the next leak hits. Your personal information deserves better.
Comments
Sort by Newest | Popular