Kaspersky Announced A TajMahal Warning
Saanvi Araav - Apr 18, 2019
Kaspersky Lab warned us about a spying framework called TajMahal
- Kaspersky Goes Full Plot Twist: From Virus Hunter to SIM Card Dealer
- How 30 Lines Of Code Destroy A 27-Ton Generator
- If You Want To Be Safe, Please Stay Away From These Fake Coronavirus Websites
News coming from New Delhi, a group of researchers at the lab of the cybersecurity firm - Kaspersky has found our a sophisticated spying platform which comes with the name TajMahal. In fact, it has been active for more than five years and seems like there is no connection to other known threat actors. The main framework of TajMahal also has up to 80 malicious modules which include some rather unique functionality, for example, the ability to steal from the printer queues.
There is also the function to grab previously seen files on flash drive devices. On the other hand, this framework is also capable of gathering Apple devices back up list, grab cookies of the browsers, and take data from CD burning.
The victim
The group at Kaspersky Lab has only found one victim of this platform so far, which is a central Asian embassy based in a foreign country. But it is very likely that there were other victims too.

The Lead Malware Analyst at Kaspersky Lab, Alexey Shulmin said that much investment could not be for just one victim, so there might be more which had fallen under its threat that we did not know of or there were other versions, or maybe both. He had not found out about the way it distributed or infected. The platform was able to remain unknown for over five years, which might be the result of its inactivity.
"Yokohama" and "Tokyo."
They added that they named this platform "TajMahal" because that is the name of the file used to exfiltrate the data. In "TajMahal" framework, there are also two main packages "Yokohama" and "Tokyo."

The targeted system of the central Asian embassy we mentioned above was infected with Yokohama and Tokyo. Kaspersky Lab said that Tokyo might be used in the first stage of the operation. While, later on, they used Yokohama to target the real targets.
Featured Stories
ICT News - Mar 24, 2026
OpenAI on the Brink: Major Setbacks Signal the Bursting of the AI Bubble
ICT News - Mar 20, 2026
Top 10 Most Popular Social Media Sites Based on User Count in 2026
ICT News - Mar 19, 2026
Billion Dollar Blunder: Meta Shuts Down Metaverse After Wasting $80,000,000,000.00
ICT News - Mar 18, 2026
X to Introduce Regional Controls for Posts and Replies
ICT News - Mar 17, 2026
Is DLSS 5 Helping Games or Hurting Developers' Creative Style?
ICT News - Mar 16, 2026
AI's Role in Warfare: US Strikes on Iran Unveiled
ICT News - Mar 15, 2026
Elon Musk's Bold Chip Venture: Tesla's Massive Fab Initiative Sparks AI Hardware...
ICT News - Mar 14, 2026
Elon Musk's High-Stakes $109 Billion Lawsuit Against OpenAI and Microsoft
ICT News - Mar 05, 2026
X Platform Implements Strict Measures Against Fake AI-Generated Videos Amid Iran...
How To - Mar 04, 2026
Getting Started with AI: A Newbie's Simple Guide
Read more
ICT News- Mar 24, 2026
OpenAI on the Brink: Major Setbacks Signal the Bursting of the AI Bubble
The era of unchecked AI hype appears to be ending, and the bubble is finally bursting.
Features- Mar 24, 2026
How to Use GeForce NOW to Play Video Games Without Actual Hardware
GeForce NOW makes PC gaming accessible to a wider audience by removing the barrier of expensive hardware.
Comments
Sort by Newest | Popular