KongTuke is a financially motivated initial access broker and malicious traffic distribution system operator active since at least 2024. It is widely tracked under the aliases TAG-124, LandUpdate808, Chaya_002, 404 TDS, and Woodgnat. The actor specializes in compromising legitimate websites, especially WordPress-based sites, and using traffic filtering and redirection infrastructure to profile visitors, evade researchers and sandboxes, and deliver malware only to selected victims. KongTuke has been linked to access sales and intrusion activity associated with ransomware ecosystems including Interlock, Rhysida, Qilin, Akira, 8Base, and Black Basta. KongTuke is notable for heavy use of social-engineering-driven initial access. Its campaigns have prominently used fake browser update themes, fake CAPTCHA verification pages, ClickFix, FileFix, and CrashFix-style paste-and-run lures that trick users into executing malicious commands through Windows Run, PowerShell, File Explorer, or other native interfaces. More recently, the actor expanded beyond web-based delivery and has used external Microsoft Teams chats while impersonating IT or help-desk personnel to persuade users to run malicious PowerShell commands, reducing user suspicion and accelerating time to persistence. The actor’s infrastructure functions as a sophisticated TDS that fingerprints victims and routes them to different payloads or decoys based on characteristics such as browser context, environment, and whether a host appears to be part of a corporate domain. Reporting indicates selective delivery logic aimed at organizational victims, including profiling of domain-joined systems and Active Directory environments. This supports the assessment that KongTuke operates as an access broker focused on obtaining valuable enterprise footholds for resale or handoff to downstream ransomware operators. KongTuke has been associated with a diverse malware ecosystem. Public reporting links it to ModeloRAT, a Python-based remote access trojan used for resilient enterprise persistence; Mistic, also tracked as MLTBackdoor, a stealthy self-deleting backdoor capable of in-memory execution; XorBee RAT, a Python reverse shell used against domain-joined systems; MintsLoader, a multi-stage PowerShell loader; and delivery relationships involving NodeSnake, D3F@ck Loader, SocGholish, GhostWeaver, StealC, HijackLoader, and SnappyClient in various campaigns. Some reporting also ties KongTuke-linked activity to malicious browser extensions and DLL sideloading chains. Observed tradecraft emphasizes stealth, flexibility, and anti-analysis. KongTuke-linked malware and loaders have used AMSI bypasses, environment scoring, anti-VM and anti-debug checks, in-memory payload execution, self-delete kill switches, scheduled-task and startup-based persistence, multiple redundant command-and-control paths, and portable Python runtimes to avoid dependence on installed interpreters. Campaigns have also used LOLBins and native utilities such as PowerShell, curl, certutil, WMIC, net, reg, and finger to blend into normal system activity. Victimology appears opportunistic but enterprise-focused. Reported targeting has included insurance, education, information technology, professional services, industrial, legal, energy, healthcare, and other corporate or critical-infrastructure environments, with activity observed in the United States and Europe. The actor’s role in the intrusion chain is typically early-stage access and foothold establishment rather than direct ransomware deployment, although its access and tooling have repeatedly appeared in incidents that later involved ransomware operators. KongTuke is best understood as both a threat cluster and service provider within the cybercrime ecosystem: an operator of malicious web-traffic routing and social-engineering infrastructure, and an initial access broker that develops or deploys stealthy remote-access tooling to compromise enterprise networks and monetize that access through ransomware-affiliated partners.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
185 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker publicly linked to infrastructure used in the ClickFix-style delivery of NodeSnake RAT associated with Interlock activity.
Financially motivated initial access broker conducting intrusions to establish and maintain long-term covert access in victim networks, then selling that access to ransomware crews.
Initial access broker conducting financially motivated opportunistic intrusions across multiple sectors, using ClickFix-style social engineering, compromised WordPress-based traffic distribution infrastructure, malicious browser extensions, Microsoft Teams lures, and stealthy custom backdoors/RATs to establish footholds and potentially sell access to ransomware affiliates.
Financially motivated initial access broker compromising corporate networks and selling access to ransomware groups; linked to Mistic/MLTBackdoor activity and ModeloRAT, and associated with ClickFix infection chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.