#ModeloRAT
ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT
ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT
ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware.
www.darkreading.com
February 17, 2026 at 9:45 PM
Hackers Hijack Microsoft Teams Accounts to Deliver ModeloRAT
Hackers Hijack Microsoft Teams Accounts to Deliver ModeloRAT
A new wave of cyberattacks is putting Microsoft Teams users on high alert across organizations worldwide. Hackers have been found hijacking Teams accounts to impersonate IT support staff and push a dangerous piece of malware called ModeloRAT directly into corporate environments, catching many organizations completely off guard and exposing serious gaps in how workplace communication tools are trusted by everyday users. This attack is part of a broader campaign tied to a threat cluster known as KongTuke, which was first publicly documented by Huntress in January of this year. The original activity involved CrashFix-style social engineering and delivered ModeloRAT through an archive hosted on Dropbox. The payload was then unpacked and executed using a bundled portable Python environment, a technique that helps the malware blend in with legitimate software activity on the infected system and avoid early detection. Analysts at Hexastrike recently investigated a new, undocumented version of this campaign and found that the attackers have significantly upgraded their approach. While the first stage of the attack follows the same general pattern seen in earlier incidents, the delivery method, execution flow, and persistence mechanisms have all changed in ways that make detection considerably harder than before. In this updated version, the threat actor contacts victims directly through fake or hijacked Microsoft Teams accounts while posing as internal IT helpdesk staff. The goal is to convince the target to run an obfuscated PowerShell command. Once executed, that command drops a ZIP archive into the system’s AppData folder, unpacks it locally, and launches the malware from a subdirectory called WPy64-31401. How ModeloRAT Evades Detection The archive that gets dropped contains a portable Python environment alongside malicious Python components. From there, the execution splits into two distinct parts: one focused on reconnaissance and the other on communicating with a remote command-and-control server. This two-part structure allows attackers to quietly gather system information while maintaining a persistent and stealthy connection back to their infrastructure, all without raising obvious red flags during normal endpoint monitoring. One of the most alarming aspects of this campaign is how effectively the malware avoids being caught. During the investigation, the samples collected had zero detections on VirusTotal, meaning the files were not flagged by any of the antivirus engines checked at the time of analysis. The malware also bypassed several major endpoint detection and response tools, which are typically a critical last line of defense in enterprise environments. Persistence is another area where this version stands apart from earlier variants. Beyond writing itself to a standard Windows startup registry key, the malware also creates a scheduled task using a randomly generated name. This makes it considerably harder for defenders to spot the malicious task among legitimate ones, and ensures the malware restarts automatically even if the registry entry gets removed. Together, these techniques show a clear and deliberate effort to stay hidden and keep running as long as possible on compromised systems. Protecting Your Organization Organizations can take several practical steps to significantly reduce the risk posed by this type of attack. One of the most straightforward moves is to review Microsoft Teams external access settings and restrict or disable messages from unknown or unverified external tenants. Since the attackers rely on reaching victims directly through Teams, limiting who can contact employees is a strong and immediate first line of defense that requires no additional tools. Security teams should also set up alerts for Dropbox downloads on corporate devices , particularly where there is no clear business need for that kind of external file access. Monitoring for ZIP file extraction inside AppData directories is another useful and practical detection approach. Since the malware relies on a portable Python environment to execute, tracking unusual instances of pythonw.exe running from user-writable paths like AppData can help surface suspicious activity early. Regularly reviewing new scheduled task registrations and registry run key changes can help catch persistence attempts before they quietly take hold. Indicators of Compromise (IoCs):- Type Indicator Description IP Address 45.61.136.94 Observed ModeloRAT C2 server IP Address 64.95.10.14 Observed ModeloRAT C2 server IP Address 64.95.12.238 Observed ModeloRAT C2 server IP Address 64.95.13.76 Observed ModeloRAT C2 server IP Address 162.33.179.149 Observed ModeloRAT C2 server File Path %APPDATA%\WPy64-31401 Malware execution directory containing portable Python environment Process pythonw.exe Portable Python used to execute malicious components from AppData Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Hackers Hijack Microsoft Teams Accounts to Deliver ModeloRAT appeared first on Cyber Security News .
cybersecuritynews.com
May 12, 2026 at 3:36 PM
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
thehackernews.com
June 25, 2026 at 9:58 AM
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
thehackernews.com
January 19, 2026 at 10:47 AM
Researchers uncovered a CrashFix campaign where a fake Chrome ad blocker crashes browsers to trick users into installing the ModeloRAT malware.
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures
thehackernews.com
January 20, 2026 at 11:10 AM
Feed: "CyberInsider"
By: Bill Mann on Monday, January 19, 2026
New CrashFix attack uses fake uBlock extension to drop ModeloRAT malware
A fake uBlock Origin Lite extension triggers a browser crash mechanism dubbed “CrashFix” to drop a Python backdoor named ModeloRAT.
cyberinsider.com
January 20, 2026 at 10:55 PM
ClickFix to CrashFix: KongTuke Used Fake Chrome Ad Blocker to Install ModeloRAT

Huntress discovers 'CrashFix,' a new attack by KongTuke hacker group using fake ad blockers to crash browsers and trick office workers into installing ModeloRAT malware.
#hackernews #news
ClickFix to CrashFix: KongTuke Used Fake Chrome Ad Blocker to Install ModeloRAT
Huntress discovers 'CrashFix,' a new attack by KongTuke hacker group using fake ad blockers to crash browsers and trick office workers into installing ModeloRAT malware.
hackread.com
January 21, 2026 at 5:54 PM
ModeloRAT turns Microsoft Teams into a backdoor, achieving domain compromise in 48 hours through social engineering. Attackers impersonate IT support, deploy Python-based malware, and escalate privileges using known Windows vulnerabilities. #infosec #cybersecurity
ModeloRAT Campaign Hijacks Microsoft Teams to Compromise Professional Service Firm Domains
ModeloRAT turns Microsoft Teams into a backdoor, achieving domain compromise in 48 hours through social engineering. Attackers impersonate IT support, deploy Python-based malware, and escalate privileges using known Windows vulnerabilities. #infosec #cybersecurity
captechgroup.com
May 13, 2026 at 6:17 PM
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
January 19, 2026 at 1:49 PM
Huntress researchers Anna Pham, Tanner Filip & Dani Lopez look into a new ClickFix variant dubbed “CrashFix” that intentionally crashes the browser then baits users into running malicious commands, and ModeloRAT. www.huntress.com/blog/malicio...
January 19, 2026 at 9:56 AM
CrashFix, a variant of the ClickFix technique, has been observed leading to the deployment of Python-based remote access trojan ModeloRAT and actions indicative of pre-ransomware activity. Get analysis, detection, hunting guidance from Microsoft Defender Experts: msft.it/63322QMW3C
New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan | Microsoft Security Blog
CrashFix crashes browsers to coerce users into executing commands that deploy a Python RAT, abusing finger.exe and portable Python to evade detection and persist on high‑value systems.
msft.it
February 5, 2026 at 10:14 PM
The malicious Python performs a series of discovery commands, before dropping the final payload `%APPDATA%\WPy64-31401\python\script.vbs` and `%STARTUP%/MonitoringService.lnk`pointing to the VBScript for persistence. This final payload is a remote access trojan and called ModeloRAT.
February 14, 2026 at 12:07 AM
Rapid7 observed a recent enterprise intrusion that began with a fake IT support Teams message, escalated via fake lock screens, Python-based RATs & a kernel exploit, then secured domain-wide credential access – all within 2 days.

Get to know #ModeloRAT: r-7.co/4npcZuB
May 13, 2026 at 4:08 PM
A new stealthy backdoor, Mistic (MLTBackdoor), has targeted insurance, education, IT, and professional sectors since April 2026, linked to an initial access broker. #CyberSecurity
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
Symantec and Carbon Black link Mistic backdoor attacks to KongTuke, using ClickFix lures and in-memory execution for stealthy access.
thehackernews.com
June 29, 2026 at 7:30 AM
Microsoft Teams Turned Into a Malware Loader, Exchange Zero Day Hits, and node-ipc Hijacked on npm

pwnhackers.substack.com/p/microsoft-...
Microsoft Teams Turned Into a Malware Loader, Exchange Zero Day Hits, and node-ipc Hijacked on npm
TLDR: Attackers are posing as IT support in Microsoft Teams chats to push PowerShell commands that install ModeloRAT malware on employee machines.
pwnhackers.substack.com
May 15, 2026 at 11:53 PM
KongTuke's MLTBackdoor sideloads into a signed Defender binary and fakes Windows Update to reach its C2. https://intel.threadlinqs.com/threat/TL-2026-2163 #ThreatIntel #BackdoorMistic #ModeloRAT #KongTuke
August 27, 2026 at 5:14 AM
The scariest malware delivery of 2026 has no attachment - it just asks you to paste the command yourself. https://intel.threadlinqs.com/threat/TL-2026-1551 #ThreatIntel #ModeloRAT #GhostClaw #MacSync
July 19, 2026 at 11:49 PM
~Symantec~
Stealthy new backdoor deployed since April 2026 may be linked to Woodgnat IAB and ModeloRAT, feeding Qilin and other ransomware operations.
-
IOCs: 142. 93. 242. 144, authorized-logins. net, thomphon. com
-
...
Backdoor.Mistic Linked to Ransomware Access Broker
www.security.com
July 6, 2026 at 5:25 AM
That fake 'verify you are human' box wants you to paste a command. Run it and you infect yourself. https://intel.threadlinqs.com/threat/TL-2026-1130 #ThreatIntel #modeloRAT #Lumma #DarkGate
July 5, 2026 at 9:39 PM
Attackers skip the exploit - they trick you into pasting the malware in yourself. That's ClickFix. https://intel.threadlinqs.com/threat/TL-2026-1127 #ThreatIntel #ModeloRAT #GateKeeper #Mistic
July 5, 2026 at 6:49 PM
Notícia da SecurityWeek

"Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’" #bolhasec
Malicious Chrome Extension Crashes Browser in ClickFix Variant 'CrashFix'
ClickFix variant CrashFix relies on a malicious Chrome extension to crash the browser and trick victims into installing the ModeloRAT RAT.
www.securityweek.com
January 30, 2026 at 8:30 PM