KongTuke, also tracked as Woodgnat, is a financially motivated cybercrime threat actor operating as an initial access broker since at least May 2024. The group is associated with enterprise intrusions that establish durable footholds and then monetize that access by supplying ransomware affiliates and other criminal actors. Public reporting has linked KongTuke/Woodgnat to ransomware ecosystems including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The actor’s tradecraft centers on social engineering and stealthy post-compromise access. KongTuke is known for using compromised WordPress sites to deliver browser-based lures and has evolved multiple user-execution schemes including ClickFix, FileFix, and CrashFix. These lures impersonate technical problems or verification prompts, such as fake browser crashes and fake CAPTCHA workflows, to persuade victims to paste and run attacker-supplied PowerShell commands. Since around April 2026, the group has also used fake IT-helpdesk interactions over Microsoft Teams to guide employees into executing malicious commands. KongTuke has been associated with custom malware including ModeloRAT, a Python-based remote access trojan, and Mistic, also tracked as MLTBackdoor, a stealthy Windows backdoor observed in intrusions since April 2026. Mistic has been used against organizations in insurance, education, information technology, and professional services. It supports covert long-term access through DLL sideloading, in-memory code execution, configurable beaconing, file management, and self-removal via a kill switch. Intrusions linked to this actor have also involved credential theft using fake login prompts and extensive abuse of native Windows utilities for command execution, reconnaissance, data transfer, and other post-exploitation activity. Victim selection appears largely opportunistic rather than geographically or sector-specific, with emphasis on organizations that can provide valuable enterprise access for resale. The actor is assessed as a cybercriminal operation rather than a state-sponsored group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated initial access broker operations targeting enterprise environments, establishing footholds and selling access to ransomware affiliates. The group is linked in this content to Mistic intrusions using social engineering lures, compromised WordPress sites, fake browser crashes, fake CAPTCHA pages, FileFix/CrashFix-style prompts, and fake Microsoft Teams helpdesk chats.
Identified as an initial access broker suspected of being linked to Backdoor.Mistic activity.
Initial access broker activity using Backdoor.Mistic and ModeloRAT to infiltrate corporate networks and sell access to ransomware operators.
Financially motivated initial access broker that establishes durable remote access in enterprise environments and sells that access to ransomware affiliates and other attackers. Recently associated with the Mistic backdoor, ModeloRAT, and the CrashFix ClickFix campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.