#KongTuke
2026-01-05 (Monday): #KongTuke domain scrroeder[.]com generated #ClickFix script for 144.31.221[.]71, but I didn't get a malware infection when I tried it today.
January 5, 2026 at 4:50 PM
2025-10-08 (Wednesday): #Kongtuke campaign fake CAPTCHA page with #ClickFix instructions. Got a full infection chain, this time. A 205MB zip download makes the #pcap take a while to load in Wireshark. Some IOCs and associated malware/artifacts at www.malware-traffic-analysis.net/2025/10/08/i...
October 9, 2025 at 4:48 AM
Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks.
KongTuke hackers now use Microsoft Teams for corporate breaches
Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks.
www.bleepingcomputer.com
May 14, 2026 at 12:12 PM
2026-09-11 (Friday): Traffic analysis exercise. I generated an infection through #KongTuke #ClickFix activity. Not sure what the malware is, but I'm sharing #pcap as an exercise, while others might find the malware files and other info useful. www.malware-traffic-analysis.net/2026/09/11/i...
September 12, 2026 at 1:12 AM
Recorded Future has published a profile on TAG-124, a name the company has given to a threat actor running a traffic distribution system (TDS) used by multiple malware operations.

The group is also known as LandUpdate808, 404TDS, KongTuke, Chaya_002.

www.recordedfuture.com/research/tag...
January 30, 2025 at 4:03 PM
2025-09-03 (Wednesday): #Kongtuke fake CAPTCHA page leads to #ClickFix style script for #LummaStealer

A #pcap of the infection traffic, the associated malware, and IOCs are at www.malware-traffic-analysis.net/2025/09/03/i...
September 3, 2025 at 6:13 PM
026-09-21 (Monday): Some IOCs from today's #KongTuke #ClickFix activity: github.com/malware-traf...
September 21, 2026 at 10:14 PM
Reposted with correct malware names:

2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT

Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity.

Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
February 3, 2026 at 3:26 AM
I finished compiling the information for #Kongtuke #ClickFix activity using the finger command on 2025-12-11, and it's now live at www.malware-traffic-analysis.net/2025/12/11/i...

I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.
December 23, 2025 at 2:33 AM
2025-01-28 (Tues): A case of web injects--malicious script injected in pages of legit websites. In this example, a site has two instances of injected script, #KongTuke and #SocGholish. A #pcap of the resulting infection, malware samples & more info at www.malware-traffic-analysis.net/2025/01/28/i...
January 29, 2025 at 5:40 AM
#kongtuke
habfan[.]com/7y7hf3j.js
December 9, 2024 at 12:46 PM
I see this as #KongTuke
December 9, 2024 at 8:27 PM
--ICE surveillance spending hits record high,
--'Mistic' backdoor linked to access broker KongTuke,
--New details on Cisco SD-WAN zero-day intrusions,
--'Edgecution' browser attack escapes the sandbox,
--'Why No Passkeys?' hall of shame emerges, 3/4
June 25, 2026 at 1:44 PM
Interesting investigative report from ADAMnetworks applicable to those running websites using the Brevo tracker or Sibforms. You may have been serving up ClickFix!

https://adamnet.works/blog/brevo-delivers-kongtuke-clickfix-to-customer-sites/
#cybersecurity
Brevo delivered ClickFix through its own infrastructure
Brevo served KongTuke ClickFix from its own infrastructure. Altered tracker scripts, forms, and unsubscribe pages delivered to customer sites.
adamnet.works
September 16, 2026 at 8:02 PM
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
thehackernews.com
June 25, 2026 at 9:58 AM
🚨 New Interlock RAT variant spotted!

Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT).

🔎 thedfirreport.com/2025/07/14/k...

#DFIR #KongTuke #InterlockRAT #FileFix
KongTuke FileFix Leads to New Interlock RAT Variant
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT). This new malware,…
thedfirreport.com
July 14, 2025 at 11:36 AM
MintsLoader malware delivers StealC info-stealer and BOINC via spam emails. Targets US/European energy & legal sectors. Uses ClickFix/KongTuke techniques & a DGA for C2 comms. StealC avoids infection in several Eastern European countries.#MintsLoaderMalware
January 27, 2025 at 7:47 AM
Saw this one earlier this month from #Kongtuke: bsky.app/profile/malw...
2025-07-03 (Thursday): #FileFix style #ClickFix page from #Kongtuke injected script in page from legitimate site at besthotelshome[.]com.

The mr.d0x article announcing FileFix calls it a ClickFix alternative, but it's really a -variant- of ClickFix. Just using File Manager instead of a Run window.
July 15, 2025 at 1:17 AM
Recorded Future's Insikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke and Chaya_002. www.recordedfuture.com/research/tag...
January 31, 2025 at 10:30 AM
💥 Upgraded Interlock RAT via fake CAPTCHA & PowerShell in KongTuke FileFix.

☁️ Uses Cloudflare Tunnel to hide C2
📡 Hardcoded IPs keep it running if blocked
🧠 Steals system info, services, and more

Report:
shorturl.at/3nVzB

#InterlockRAT #KongTuke #Malware #Cybersecurity
July 15, 2025 at 6:56 AM
ClickFix to CrashFix: KongTuke Used Fake Chrome Ad Blocker to Install ModeloRAT

Huntress discovers 'CrashFix,' a new attack by KongTuke hacker group using fake ad blockers to crash browsers and trick office workers into installing ModeloRAT malware.
#hackernews #news
ClickFix to CrashFix: KongTuke Used Fake Chrome Ad Blocker to Install ModeloRAT
Huntress discovers 'CrashFix,' a new attack by KongTuke hacker group using fake ad blockers to crash browsers and trick office workers into installing ModeloRAT malware.
hackread.com
January 21, 2026 at 5:54 PM
A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors.
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors.
www.bleepingcomputer.com
June 24, 2026 at 10:42 AM
🤖 Mistic: New backdoor by ransomware access broker KongTuke. Targets insurance, education, IT orgs. HTTPS C2, scheduled task persistence. Technical analysis with IoCs.
https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/
June 24, 2026 at 11:39 AM