KongTuke is a traffic distribution system (TDS), also tracked as TAG-124 and js.LandUpdate808, that compromises WordPress websites and injects JavaScript to route visitors into staged malware-delivery workflows. First observed in 2024, it commonly presents fake CAPTCHA or browser-verification lures that use ClickFix or FileFix social engineering to induce victims to paste and execute attacker-supplied commands. These commands retrieve and execute subsequent payloads, making KongTuke a delivery framework rather than a single fixed final-stage payload.
KongTuke operations have delivered a range of malware, including loaders, Node.js backdoors and RATs, and ransomware-associated payloads. Observed Windows-focused chains have abused DLL sideloading with legitimate signed Firefox binaries and Rust-based DLLs masquerading as Firefox components. These components include loader, persistence, and command-and-control functions. KongTuke infrastructure has used HTTPS beaconing and domain-generation techniques to rotate command-and-control destinations. Some campaigns have also used blockchain-based configuration retrieval to make infrastructure rotation and static detection more difficult.
KongTuke is primarily associated with compromised websites, especially WordPress installations, and targets their visitors through convincing verification-themed landing pages. No specific threat actor attribution is established with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
In most scenarios, once users interact with the Fix or Verify button in the lure, the button will covertly copy an obfuscated PowerShell command to the clipboard and present the user with “verification steps.”
Recent weeks have seen a rise in ClickFix social engineering campaigns delivering the KongTuke malware through DLL sideloading.
The malware communicates with its C2 servers over HTTPS, beaconing approximately every 30 seconds
HTTP/S was used for panel APIs, JS staging, challenge/response traffic, and ClickFix command retrieval.
222 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A traffic distribution system using compromised WordPress sites to deploy malicious code that may lead to malware.
KongTuke is delivered via ClickFix social engineering and DLL sideloading using legitimate signed Mozilla Firefox binaries. The campaign uses Rust-written malicious DLLs, including an initial loader, a persistence DLL, and a primary C2 implant. It uses a DGA to generate C2 domains and communicates with command-and-control servers over HTTPS with roughly 30-second beaconing.
KONGTUKE6
Referenced as a delivery chain in which ClickFix was used to distribute PhantomRelay variants in related cybercrime activity clusters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.