KongTuke is a financially motivated initial access broker and malware-distribution operation active since at least 2024. Also tracked as LandUpdate808, TAG-124, Chaya_002, 404 TDS, and Woodgnat, it operates a multi-tenant traffic distribution system built around compromised WordPress websites. The operation obtains corporate footholds that support downstream ransomware activity, with recurring links to Interlock and Rhysida delivery chains and ModeloRAT infections preceding Qilin deployment. Its targeting is opportunistic, with campaigns affecting industrial, legal, and energy organizations in the United States and Europe. KongTuke injects JavaScript into compromised websites to profile visitors and present fake CAPTCHA verification or browser-update lures. Its ClickFix attacks manipulate clipboard contents and persuade users to execute commands through the Windows Run dialog. The operation also uses CrashFix, in which a malicious Chrome extension masquerading as an ad blocker deliberately exhausts browser resources and presents fraudulent repair instructions. Microsoft Teams messages impersonating IT support provide another delivery channel for ModeloRAT. Execution chains abuse legitimate Windows utilities, PowerShell, and portable Python or Node.js runtimes to retrieve and execute malicious code. Victim screening checks domain membership, installed security products, virtualization, and analysis tools, allowing selective delivery to enterprise systems. KongTuke operates MintsLoader and deploys ModeloRAT, a Python remote-access trojan supporting host reconnaissance, remote command execution, additional payload delivery, and persistent access. Observed persistence mechanisms include user-level registry autoruns and scheduled tasks. Layered obfuscation, encrypted payloads, in-memory execution, anti-analysis checks, and legitimate signed interpreters reduce visibility and impede analysis.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
254 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ClickFix/web-inject delivery campaign associated in the content with delivery of the Interlock RAT chain through compromised websites and fake human-verification pages.
Named activity cluster associated with ClickFix activity that uses a fake verification page to induce users to paste instructions into the Windows Run dialog. The reference describes a traffic-analysis exercise involving an infected Windows host, captured HTTPS traffic, a ClickFix script, and retrieved malware artifacts, but does not identify specific malware families.
An initial-access-broker cluster conducting ClickFix/CrashFix social-engineering campaigns. It abuses the legitimate Node.js runtime to execute malicious JavaScript, uses EtherHiding for resilient C2 discovery, and deploys persistent backdoors and post-compromise tooling.
Mentioned only in the title of a cited external report in connection with the CrashFix campaign and ModeloRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.