KongTuke is a traffic distribution system and malware delivery framework first observed in 2024 and active through at least 2026. It is associated with compromised WordPress websites that inject malicious JavaScript and redirect visitors into ClickFix and fake CAPTCHA social-engineering flows. The operation is also tracked under aliases including 404 TDS, Chaya_002, LandUpdate808, TAG-124, and js.kongtuke.
KongTuke functions primarily as an initial access and payload delivery ecosystem rather than a single monolithic payload. Observed campaigns have used compromised websites to stage multi-step browser-based infection chains that manipulate the clipboard, coerce users into pasting and executing commands, and then retrieve follow-on malware. Delivery methods documented for KongTuke include ClickFix, fake CAPTCHA verification pages, and FileFix-style paste-and-run abuse. In multiple cases, KongTuke activity has led to the deployment of additional malware families including MintsLoader, WARMCOOKIE, D3F@ck Loader, Mocha Manakin, GhostWeaver RAT, and ransomware such as Rhysida and Interlock.
Infrastructure and delivery tradecraft show a high degree of adaptability. KongTuke has been observed leveraging compromised WordPress sites as redirectors or loaders, rotating lure domains, and in some campaigns retrieving command-and-control configuration dynamically from a Polygon smart contract rather than hardcoding infrastructure in scripts. This blockchain-backed configuration model increases resilience and complicates static detection. Separate reporting also links KongTuke to domain-generation-algorithm-based command-and-control, with generated domains themed around infrastructure and security terminology and beaconing over HTTPS at regular intervals.
On Windows, KongTuke campaigns have used DLL sideloading with legitimate signed Mozilla Firefox binaries. Malicious Rust-based DLLs masquerading as Firefox components have been identified serving distinct roles, including an initial loader, a persistence module, and a primary command-and-control implant. Observed infection chains also include staged JavaScript, token and gateway handling, clipboard manipulation, command execution, archive retrieval, and persistence via scheduled tasks.
KongTuke has been linked to broader criminal delivery ecosystems and overlapping intrusion activity. Trustwave SpiderLabs and other defenders have attributed fake verification and ClickFix activity on compromised sites to KongTuke. WithSecure also observed a KongTuke ClickFix delivery chain overlapping with PhantomRelay-related activity in 2026, though that does not by itself establish exclusive ownership by a single threat actor. Overall, KongTuke is best understood as a flexible web-based malware distribution and initial access framework centered on compromised websites, social engineering, staged loaders, and delivery of downstream payloads against Windows users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware communicates with its C2 servers over HTTPS, beaconing approximately every 30 seconds
213 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KongTuke is delivered via ClickFix social engineering and DLL sideloading using legitimate signed Mozilla Firefox binaries. The campaign uses Rust-written malicious DLLs, including an initial loader, a persistence DLL, and a primary C2 implant. It uses a DGA to generate C2 domains and communicates with command-and-control servers over HTTPS with roughly 30-second beaconing.
KONGTUKE6
Referenced as a delivery chain in which ClickFix was used to distribute PhantomRelay variants in related cybercrime activity clusters.
KongTuke is referenced as the malware involved in an infection chain delivered via a compromised site, intermediary JavaScript and gateway stages, and final BAT/ZIP payload retrieval.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.