ModeloRAT is a Python-based remote access trojan for Windows, first observed in January 2026. It is associated with the financially motivated initial access broker Woodgnat, also known as KongTuke, and is selectively deployed to domain-joined hosts in enterprise environments. It provides durable remote access and has been observed in intrusions that subsequently deployed Qilin ransomware. ModeloRAT has also appeared alongside the Mistic backdoor.
Delivery mechanisms include ClickFix fake CAPTCHA lures on compromised WordPress websites, CrashFix browser-repair pretexts, and Microsoft Teams messages impersonating IT support. The CrashFix chain uses a malicious Chrome extension called NexShield, promoted as an ad blocker through sponsored search results. The extension deliberately makes the browser unresponsive and presents a fake repair prompt that persuades users to execute attacker-controlled commands. Multi-stage command and PowerShell execution retrieves a portable WinPython environment and launches ModeloRAT without requiring an existing Python installation. Deployment stages check domain membership, enumerate antivirus products, and screen for analysis tools and virtualized environments.
ModeloRAT collects detailed host information, including network configuration, active connections, system identity, privilege context, processes, services, storage, and domain membership. Operators can execute arbitrary PowerShell commands, deploy executables and DLLs, run additional Python payloads, update the implant, and terminate it. Persistence uses user-level registry autorun entries, with commands available to restore removed persistence; associated deployments have also used scheduled tasks.
Command-and-control communication uses HTTP with RC4 encryption and zlib-compressed JSON. Adaptive beaconing supports rapid polling during active operator interaction and longer intervals after repeated connection failures. Runtime construction of command-and-control addresses, junk code, hidden subprocess windows, and obfuscated supporting payloads hinder detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators | A newer Python-based backdoor called ModeloRAT, deployed by the TAG-124 traffic distribution network tied to Interlock, further extends NodeSnake’s code structure and uses identical network validation bytes.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Both delivery paths — CrashFix browser-extension abuse and ClickFix/fake CAPTCHA chains — ultimately converge on the same objective: the deployment of the Python-based modeloRAT.
The Node.js technique has been employed alongside ModeloRAT and Mistic, both assessed to be the work of the initial-access broker KongTuke/Woodgnat.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
They hijack normal WordPress websites to push fake technical alerts. In a recent tactic from early 2026 called CrashFix, they purposely froze a victim’s web browser and displayed a message telling them to copy-paste a command to fix the issue.
“Eight command types give operators full remote code execution.”
Woodgnat attack chains abuse node.exe to execute attacker JavaScript and chain PowerShell and Windows command-line tools.
Woodgnat attack chains abuse node.exe to execute attacker JavaScript and chain PowerShell and Windows command-line tools.
Persistence is established through several redundant mechanisms, including... VBScript launchers
INTERPRETED_SCRIPT drops and runs another Python script with the bundled interpreter.
Attackers downloaded the official Node.js installer and used the trusted, signed node.exe runtime to execute attacker JavaScript and deploy a malicious implant.
That script, wrapped in stacked Base64 and XOR layers... ModeloRAT... builds C2 IP addresses through string concatenation... and ends with roughly 70 lines of junk code.
The extension copies a command to your clipboard disguised as edge.exe -fix-browser... Copy finger.exe out of System32 and rename it ct.exe to dodge name-based detection.
Delete the script so nothing is left on disk after it runs... Remove-Item "$env:APPDATA\script.ps1".
"...the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
“ModeloRAT is ... delivered only to domain-joined hosts in enterprise environments.”
The group then conducts extensive reconnaissance using built-in Windows tooling, enumerating domain users, groups, computers and sessions with net.exe
It checks running processes against a list of more than 50 analysis tools and VM indicators.
Then it reads the domain field from systeminfo and reports back with a marker, ABCD111 for standalone WORKGROUP hosts and BCDA222 for domain-joined ones.
It can also create new folders, and check for additional commands from the attacker-controlled command-and-control (C2) server.
“C2 traffic uses HTTP port 80 with RC4 encryption, zlib-compressed JSON, and adaptive beaconing intervals.”
"The malware was also distributed in a different ClickFix campaign that involved running commands carrying out a Domain Name System (DNS) lookup to retrieve the next-stage payload, with Microsoft noting that the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
For a domain-joined host, the C2 returns a command that grabs Winpython.zip, a Dropbox-hosted archive holding the portable WinPython build WPy64-31401, and starts the RAT with it.
"...the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access tool observed in attacks abusing Node.js; believed to have been developed by the initial-access broker Woodgnat/KongTuke.
Remote-access malware associated in the report with KongTuke/Woodgnat attack activity leveraging Node.js and ClickFix.
Python-based Windows remote-access trojan delivered in the CrashFix campaign through a fake NexShield Chrome extension. It targets domain-joined enterprise hosts and uses HTTP over port 80 with RC4 encryption and zlib-compressed JSON for C2. Its eight command types support remote code execution, payload deployment, self-update, and implant termination.
Python-based Windows RAT delivered as the final payload in the CrashFix campaign. It uses a bundled portable Python runtime, maintains Run-key persistence, performs reconnaissance, executes arbitrary PowerShell commands, deploys EXE/DLL/Python payloads, updates itself, and supports clean termination. Its HTTP C2 uses RC4-encrypted, zlib-compressed JSON with adaptive beaconing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.