KongTuke is a financially motivated initial access broker and malicious traffic distribution system active since at least 2024. It is also tracked as Chaya_002, LandUpdate808, TAG-124, 404 TDS, and Woodgnat. The actor compromises legitimate websites, especially WordPress sites, and uses layered traffic distribution infrastructure to profile visitors, evade researchers and sandboxes, and redirect selected victims to malware delivery chains. KongTuke is closely associated with fake browser update and fake CAPTCHA lures, including ClickFix, FileFix, and other paste-and-run social engineering techniques that coerce users into executing malicious commands. KongTuke has been linked to delivery of multiple malware families and custom tooling, including ModeloRAT, Mistic, MintsLoader, D3F@ck Loader, and XorBee RAT, and has also been associated with SocGholish-related delivery ecosystems. Observed tradecraft includes reconnaissance and victim profiling, anti-analysis checks, use of legitimate binaries and interpreters, PowerShell-based staging, DLL sideloading, in-memory payload execution, scheduled-task persistence, and credential theft through fake login prompts. Campaigns have used compromised websites, malicious browser extensions, Microsoft Teams social engineering, and traffic-routing logic that distinguishes higher-value organizational victims such as domain-joined enterprise systems. The actor’s business model is consistent with access brokerage: obtaining footholds in corporate environments and facilitating downstream intrusions by other criminal groups. KongTuke-linked access has been associated with ransomware ecosystems including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Targeting appears largely opportunistic but has repeatedly affected organizations in insurance, education, information technology, professional services, and critical infrastructure-related environments, with reporting also tying TAG-124 infrastructure to healthcare-focused ransomware activity. Overall, KongTuke functions as a resilient malware delivery and access-enablement service that improves infection efficiency for financially motivated cybercrime operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
237 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access actor using ClickFix to deploy the Mistic backdoor, enabling downstream compromises including by Qilin affiliates.
Traffic distribution system using compromised WordPress sites to deploy malicious code, with campaigns in 2026 often leveraging paste-and-run for initial execution.
Initial access broker publicly linked to infrastructure used in the ClickFix-style delivery of NodeSnake RAT associated with Interlock activity.
Financially motivated initial access broker conducting intrusions to establish and maintain long-term covert access in victim networks, then selling that access to ransomware crews.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.