KongTuke is a financially motivated initial access broker and malicious traffic distribution system active since at least 2024. It is also tracked as TAG-124, LandUpdate808, Chaya_002, 404 TDS, and Woodgnat. The actor is known for compromising legitimate websites, especially WordPress sites, and using traffic filtering and redirection infrastructure to deliver malware only to selected victims while excluding researchers and sandbox environments. KongTuke has been publicly linked to access operations that support downstream ransomware activity involving Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. KongTuke commonly relies on social-engineering-driven initial access, particularly ClickFix, fake CAPTCHA, CrashFix, FileFix, and paste-and-run lures that trick users into executing malicious commands. More recent activity also includes impersonation of IT or help-desk personnel through external Microsoft Teams chats to induce execution of PowerShell-based stagers. The actor has used compromised websites, malicious browser-extension themes, and collaboration-platform lures to establish footholds in enterprise environments. Tooling associated with KongTuke includes ModeloRAT, Mistic (also tracked as MLTBackdoor), XorBee RAT, MintsLoader, D3F@ck Loader, GateKeeper, and other Python- and .NET-based payloads. Observed capabilities include deployment of stealthy backdoors, in-memory payload execution, DLL sideloading, use of legitimate interpreters and LOLBins such as PowerShell, curl, finger.exe, certutil, WMIC, and Node.js, and anti-analysis checks for virtualized or monitored environments. Mistic in particular has been associated with in-memory execution, self-deletion, file-management functions, and Beacon Object File loading, while ModeloRAT and XorBee RAT have been used to maintain persistent remote access and profile victims, including distinguishing domain-joined enterprise systems from less valuable standalone hosts. KongTuke’s operations are consistent with an access-broker model rather than direct ransomware deployment in every case. The actor appears to obtain footholds opportunistically across corporate environments and either monetize them directly through follow-on malware delivery, credential theft, and cryptocurrency theft, or sell access to ransomware affiliates. Reported victim sectors include insurance, education, information technology, professional services, industrials, legal services, and energy, with notable emphasis on enterprise and critical-infrastructure-adjacent organizations. The actor demonstrates mature defense evasion and post-compromise tradecraft, including persistence establishment, reconnaissance, credential theft, lateral movement support, and stealth-focused malware design.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access actor using ClickFix to deploy the Mistic backdoor, enabling downstream compromises including by Qilin affiliates.
Traffic distribution system using compromised WordPress sites to deploy malicious code, with campaigns in 2026 often leveraging paste-and-run for initial execution.
Initial access broker publicly linked to infrastructure used in the ClickFix-style delivery of NodeSnake RAT associated with Interlock activity.
Financially motivated initial access broker conducting intrusions to establish and maintain long-term covert access in victim networks, then selling that access to ransomware crews.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.