KongTuke is a financially motivated initial access broker and malicious traffic distribution system operator active since at least 2024. It is also tracked as TAG-124, LandUpdate808, Chaya_002, 404 TDS, and Woodgnat. The actor is known for compromising legitimate websites, especially WordPress-based sites, and using traffic filtering and redirection logic to steer selected victims to malware delivery chains while excluding researchers and low-value targets. KongTuke has been publicly linked to access operations that support ransomware and other cybercrime, including activity associated with Interlock, Rhysida, Qilin, Akira, 8Base, and Black Basta. KongTuke’s hallmark tradecraft is socially engineered user execution through fake browser-update, fake CAPTCHA, ClickFix, CrashFix, and FileFix lures. These campaigns commonly coerce victims into pasting and running obfuscated commands through the Windows Run dialog, PowerShell, or other native interfaces. More recent operations also used external Microsoft Teams chats impersonating IT or help-desk personnel to induce execution of malicious commands, indicating an expansion from web-only delivery to collaboration-platform abuse. The actor has repeatedly adopted LOLBins and native tooling in its infection chains, including PowerShell, curl, certutil, WMIC, net utilities, registry tools, and finger.exe, and has shown sustained interest in paste-and-run execution patterns. The group’s malware ecosystem includes ModeloRAT, Mistic (also tracked as MLTBackdoor), XorBee RAT, MintsLoader, D3F@ck Loader, and GateKeeper, with additional links reported to SocGholish-related delivery infrastructure. ModeloRAT is a Python-based remote access trojan associated with enterprise-focused intrusions and resilient persistence. Mistic is a stealth-oriented backdoor used in financially motivated intrusions, notable for in-memory payload execution, DLL sideloading, and self-deletion. XorBee RAT is another Python-based remote access tool observed in KongTuke delivery chains, particularly against domain-joined environments. MintsLoader activity has also been associated with TAG-124/LandUpdate808 as a primary sustained operator. Observed post-exploitation behavior indicates a focus on establishing durable footholds suitable for resale rather than immediate ransomware deployment by KongTuke itself. Tooling and workflows support host profiling, domain membership checks, Active Directory reconnaissance, credential theft, screenshot capture, file transfer, configurable beaconing, in-memory execution, and multiple persistence mechanisms. Several campaigns appear designed to distinguish consumer systems from organizational networks and preferentially deliver more capable payloads to enterprise victims. This targeting pattern is consistent with an access-broker model serving downstream ransomware affiliates and other financially motivated operators. KongTuke has targeted organizations in sectors including insurance, education, information technology, professional services, industrial, legal, and energy, with broader opportunistic exposure through compromised websites. Reporting has also linked its infrastructure and delivery services to healthcare-focused ransomware activity and to malware campaigns affecting critical infrastructure victims. The actor’s operational style emphasizes stealth, flexible delivery, rapid adaptation of social-engineering themes, and continual refinement of traffic distribution logic to maximize infection success and evade detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Traffic distribution system using compromised WordPress sites to deploy malicious code, with campaigns in 2026 often leveraging paste-and-run for initial execution.
Initial access broker publicly linked to infrastructure used in the ClickFix-style delivery of NodeSnake RAT associated with Interlock activity.
Financially motivated initial access broker conducting intrusions to establish and maintain long-term covert access in victim networks, then selling that access to ransomware crews.
Initial access broker conducting financially motivated opportunistic intrusions across multiple sectors, using ClickFix-style social engineering, compromised WordPress-based traffic distribution infrastructure, malicious browser extensions, Microsoft Teams lures, and stealthy custom backdoors/RATs to establish footholds and potentially sell access to ransomware affiliates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.