Kaspersky researcher identifies sophisticated new spyware, dubbed TajMahal, that went undetected for five years and is from an as-yet unknown source
IT'S NOT EVERY day that security researchers discover a new state-sponsored hacking group. Even rarer is the emergence of one whose spyware … Tweets: @dcuthbert , @dcuthbert , @dcuthbert , and @a_greenberg Tweets: Daniel Cuthbert / @dcuthbert : For all that's reported, there's so many others going on that are far more advanced. I.e limited time campaign, fat of the land, all driven by our infosec research Daniel Cuthbert / @dcuthbert : For example, how the group got caught, OPSEC failures and technical approaches new groups can learn and adopt. As a building community, we've totally sucked at fixing this. It's just too easy for any cracker to get away with mediocre shit and seem l33t. Daniel Cuthbert / @dcuthbert : I do love the fact that more eyes are now seemingly uncovering and reporting on some pretty brazen campaigns. https://www.wired.com/... my worry is that whilst these make for good reading, it does nothing to stop them. Seemingly, these exposing articles are used to better others Andy Greenberg / @a_greenberg : Kaspersky researchers found a puzzle inside a Central Asian country's embassy: Highly versatile spyware infecting its network, called TajMahal, with 80 distinct modules and no fingerprints of any known hacker groups. It had gone undetected for five years. http://www.wired.com/...
Context & Ripple Effects
Kaspersky has built its research brand on excavating espionage toolkits that ran unnoticed for years — the Stuxnet-linked Equation Group report, and more recently Slingshot, which hid on victim machines for six years. TajMahal extends that pattern: roughly 80 modules, five years of stealth, and no claimed owner.
The disclosure cuts both ways, and Kaspersky knows it. Its Slingshot write-up reportedly exposed a US Joint Special Operations Command operation, and the firm itself was later implicated in the theft of NSA cyber data via its own software — so every new APT report now carries geopolitical risk alongside the defensive value.
First-order effects
- Defenders gain signatures and a module inventory for a toolkit that operated invisibly for five years, while the unnamed operator loses its longest-lived access wherever Kaspersky telemetry reaches.
Second-order effects
- With no attributed sponsor, other governments and security vendors will race to claim or contest the attribution — and if a state is eventually named, its remaining operations face the same exposure dynamic that burned the Slingshot operator.
Third-order effects
- A five-year dwell time for an 80-module implant points to a structural detection gap in endpoint security, and the line between state APT tradecraft and commercial spyware keeps blurring — Google's finding that Russia-linked APT29 used exploits 'identical or strikingly similar' to NSO Group and Intellexa's shows toolkits circulating across the state-mercenary divide.
The trend: Antivirus firms are functioning as de facto intelligence services whose APT disclosures simultaneously arm defenders, burn state operators, and reshape attribution politics.