The group is also known as LandUpdate808, 404TDS, KongTuke, Chaya_002.
www.recordedfuture.com/research/tag...
The group is also known as LandUpdate808, 404TDS, KongTuke, Chaya_002.
www.recordedfuture.com/research/tag...
A #pcap of the infection traffic, the associated malware, and IOCs are at www.malware-traffic-analysis.net/2025/09/03/i...
A #pcap of the infection traffic, the associated malware, and IOCs are at www.malware-traffic-analysis.net/2025/09/03/i...
2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT
Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity.
Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver RAT
Today's ClickFix uses the "finger" command, a tactic seen in previous ClickFix activity.
Further details available at www.malware-traffic-analysis.net/2026/02/02/i...
I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.
I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.
--'Mistic' backdoor linked to access broker KongTuke,
--New details on Cisco SD-WAN zero-day intrusions,
--'Edgecution' browser attack escapes the sandbox,
--'Why No Passkeys?' hall of shame emerges, 3/4
--'Mistic' backdoor linked to access broker KongTuke,
--New details on Cisco SD-WAN zero-day intrusions,
--'Edgecution' browser attack escapes the sandbox,
--'Why No Passkeys?' hall of shame emerges, 3/4
https://adamnet.works/blog/brevo-delivers-kongtuke-clickfix-to-customer-sites/
#cybersecurity
https://adamnet.works/blog/brevo-delivers-kongtuke-clickfix-to-customer-sites/
#cybersecurity
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT).
🔎 thedfirreport.com/2025/07/14/k...
#DFIR #KongTuke #InterlockRAT #FileFix
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware group’s remote access trojan (RAT).
🔎 thedfirreport.com/2025/07/14/k...
#DFIR #KongTuke #InterlockRAT #FileFix
☁️ Uses Cloudflare Tunnel to hide C2
📡 Hardcoded IPs keep it running if blocked
🧠 Steals system info, services, and more
Report:
shorturl.at/3nVzB
#InterlockRAT #KongTuke #Malware #Cybersecurity
☁️ Uses Cloudflare Tunnel to hide C2
📡 Hardcoded IPs keep it running if blocked
🧠 Steals system info, services, and more
Report:
shorturl.at/3nVzB
#InterlockRAT #KongTuke #Malware #Cybersecurity
Huntress discovers 'CrashFix,' a new attack by KongTuke hacker group using fake ad blockers to crash browsers and trick office workers into installing ModeloRAT malware.
#hackernews #news
Huntress discovers 'CrashFix,' a new attack by KongTuke hacker group using fake ad blockers to crash browsers and trick office workers into installing ModeloRAT malware.
#hackernews #news
https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/
https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/