ModeloRAT is a Python-based remote access trojan/backdoor associated with the financially motivated initial access broker Woodgnat, also known publicly as KongTuke. Reporting links its use to enterprise intrusions and to ransomware access operations involving Qilin, Akira, Rhysida, Black Basta, Interlock, and 8Base. It has been observed delivered through social-engineering campaigns including ClickFix/CrashFix-style lures on compromised WordPress infrastructure and fake or hijacked Microsoft Teams helpdesk chats that trick victims into executing attacker-supplied PowerShell commands. In some campaigns, victims downloaded a portable WinPython environment from Dropbox or other attacker-controlled infrastructure, after which ModeloRAT was launched via pythonw.exe and persisted through artifacts such as VBScript launchers, Startup shortcuts, Run keys, and scheduled tasks.
High-confidence reported capabilities include collecting system and user information, capturing screenshots, exfiltrating files, and maintaining resilient long-term access through multiple command-and-control paths and multiple persistence triggers. Related reporting states that newer variants used a five-server command-and-control pool with automatic failover, randomized URL paths, self-update capability, and multiple independent access channels including a primary RAT, a reverse shell, and a TCP backdoor. Symantec also reported ModeloRAT deployed alongside the stealthy backdoor Mistic in at least one intrusion, reinforcing the association with Woodgnat/KongTuke access-broker activity.
Known indicators directly mentioned in the content for ModeloRAT-related activity include command-and-control IPs 45.61.136.94, 64.95.10.14, 64.95.12.238, 64.95.13.76, and 162.33.179.149, and execution from %APPDATA%\WPy64-31401 via pythonw.exe in one Teams-delivered campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators | A newer Python-based backdoor called ModeloRAT, deployed by the TAG-124 traffic distribution network tied to Interlock, further extends NodeSnake’s code structure and uses identical network validation bytes.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware has been observed operating alongside ModeloRAT, a Python-based remote access trojan previously linked to the financially motivated group tracked as Woodgnat, also known publicly as KongTuke.
The malware has been observed operating alongside ModeloRAT, a Python-based remote access trojan previously linked to the financially motivated group tracked as Woodgnat, also known publicly as KongTuke.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
They hijack normal WordPress websites to push fake technical alerts. In a recent tactic from early 2026 called CrashFix, they purposely froze a victim’s web browser and displayed a message telling them to copy-paste a command to fix the issue.
Persistence is established through several redundant mechanisms, including... scheduled tasks.
"...trick them into running arbitrary commands under the pretext of running a security scan."
attackers used social engineering lures, including fake browser crashes and fake CAPTCHA tests, to trick victims into executing attacker-supplied PowerShell commands.
Persistence is established through several redundant mechanisms, including... VBScript launchers
Persistence is established through several redundant mechanisms, including... scheduled tasks.
The campaign used a malicious Chrome extension named NexShield, disguised as an ad blocker, to intentionally crash victims’ browsers and trick them into running PowerShell commands that led to the deployment of ModeloRAT.
loaded from a DLL named EndpointDlp.dll, a name associated with Microsoft endpoint-security tooling. This would help the backdoor blend in with trusted software... Persistence is established through several redundant mechanisms, including Run-key entries that masquerade as legitimate remote-access software, using names such as AnyDesk, Splashtop and Comms.
"...the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
performing Active Directory and Kerberoasting queries against accounts with service principal names to harvest crackable credentials
The group then conducts extensive reconnaissance using built-in Windows tooling, enumerating domain users, groups, computers and sessions with net.exe
It can also create new folders, and check for additional commands from the attacker-controlled command-and-control (C2) server.
The RAT uses RC4-encrypted command-and-control (C2) communications and is built for resilience, with multiple independent C2 paths on separate infrastructure.
"The malware was also distributed in a different ClickFix campaign that involved running commands carrying out a Domain Name System (DNS) lookup to retrieve the next-stage payload, with Microsoft noting that the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
The backdoor can run remote payloads directly in memory... Upload/download a file... Once a command is executed, a multi-stage PowerShell chain downloads and unpacks a portable WinPython environment... Finger.exe... retrieve obfuscated payloads.
"...the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
Mistic is a stealthy backdoor used by KongTuke-linked actors to keep long-term access in ransomware-targeted networks.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based remote access trojan observed alongside Mistic and previously linked to Woodgnat/KongTuke.
A remote access trojan linked in the reporting to Backdoor.Mistic.
A remote access tool deployed by the Woodgnat/KongTuke group as part of operations that broker access to ransomware affiliates.
A KongTuke-linked remote access trojan/backdoor associated with intrusions where Mistic was later deployed. The content notes it has spread through Microsoft Teams social engineering and is suspected to be part of Woodgnat's custom stealthy remote access tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.