KongTuke
KongTuke is a financially motivated initial access broker and traffic distribution system (TDS) active since at least 2024, also tracked as Woodgnat, 404 TDS, Chaya_002, LandUpdate808, and TAG-124. The reporting describes it as an access-broker service rather than a single malware family: it compromises legitimate, especially WordPress, websites, injects external JavaScript, and uses fake CAPTCHA, ClickFix, CrashFix, and FileFix-style social engineering to trick users into executing obfuscated PowerShell or other commands that fetch second-stage payloads. More recently, it has also used external Microsoft Teams chats while impersonating IT or help-desk staff to obtain persistent access to corporate networks in minutes. KongTuke has been linked to financially motivated intrusions against organizations in sectors including insurance, education, IT, professional services, industrial, legal, and energy, and reporting also ties its infrastructure to healthcare and other critical infrastructure targeting through downstream ransomware customers. Its business model is to compromise corporate networks and sell access to other criminals, including ransomware operators. Content directly links KongTuke-associated access or infrastructure to Qilin, Interlock, Rhysida, Akira, 8Base, Black Basta, and AlphV/BlackCat. The actor’s tooling and delivery ecosystem includes ModeloRAT, a Python RAT/backdoor attributed to the group; Mistic, also tracked as MLTBackdoor, which Symantec and Carbon Black linked to KongTuke with low confidence; XorBee RAT; MintsLoader; D3F@ck Loader; Emmenhtal; Remcos; AsyncRAT; and Interlock RAT. ModeloRAT has been observed in ClickFix and Microsoft Teams social-engineering campaigns, while Mistic has been delivered via multi-stage ClickFix chains and uses DLL sideloading, in-memory execution, and self-deletion. Reporting also notes use of WinPython, Node.js, finger.exe, a fake NexShield browser extension, and the encrypted GateKeeper .NET payload. Observed tactics and techniques in the content include compromised-site web injects, SEO poisoning, TDS-based victim filtering and redirection, fake browser update and CAPTCHA lures, clipboard hijacking, paste-and-run execution, abuse of LOLBins such as PowerShell, curl, certutil, WMIC, net.exe, reg.exe, and finger.exe, DLL sideloading, in-memory payload execution, scheduled-task and Run-key persistence, anti-analysis checks, and victim profiling to distinguish standalone from domain-joined enterprise systems. Multiple reports describe KongTuke as operating broad, opportunistic campaigns and then assessing which footholds can be sold onward. The content also notes links between TAG-124/LandUpdate808 infrastructure and SocGholish, TA866/Asylum Ambuscade, and Interlock, but does not establish those as aliases or sub-groups of KongTuke.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Insurance
- Software & Services
- Commercial & Professional Services
- Academia & Research
Tradecraft
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
Observables
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated initial access broker conducting intrusions to establish and maintain long-term covert access in victim networks, then selling that access to ransomware crews.
Initial access broker conducting financially motivated opportunistic intrusions across multiple sectors, using ClickFix-style social engineering, compromised WordPress-based traffic distribution infrastructure, malicious browser extensions, Microsoft Teams lures, and stealthy custom backdoors/RATs to establish footholds and potentially sell access to ransomware affiliates.
Financially motivated initial access broker compromising corporate networks and selling access to ransomware groups; linked to Mistic/MLTBackdoor activity and ModeloRAT, and associated with ClickFix infection chains.
Initial access broker active since at least 2024, linked to the Mistic backdoor and ModeloRAT, compromising corporate networks and selling access to ransomware groups.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.