ModeloRAT is a Python-based remote access trojan targeting domain-joined Windows systems in enterprise environments. First observed in January 2026, it has been associated with the financially motivated initial-access broker Woodgnat, also known as KongTuke. The malware has been observed in CrashFix ClickFix campaigns involving a malicious browser extension that causes browser instability before persuading victims to execute attacker-controlled commands. KongTuke has also used Microsoft Teams helpdesk impersonation lures to induce victims to run malicious PowerShell commands that lead to ModeloRAT deployment.
ModeloRAT is deployed with a portable Python environment and establishes user-level persistence through multiple startup triggers. It profiles hosts, including domain membership and security software, and selectively deploys to domain-joined systems. Its command-and-control protocol uses HTTP, RC4 encryption, compressed JSON, and adaptive beacon intervals. Operator tasking supports host reconnaissance, arbitrary command execution, deployment and execution of additional payloads, restoration of persistence, implant updates, and clean termination or removal. The malware incorporates anti-analysis checks, obfuscation, runtime construction of configuration values, and hidden subprocess execution to hinder detection and analysis. Its focus on enterprise domain hosts and post-compromise tasking makes it suitable for establishing durable access that may be used to support ransomware-affiliate operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Local privilege escalation exploit CVE-2023-36036 (JunkFiction-crypted) ... CVE CVE-2023-36036 Local privilege escalation exploit used by Interlock and ModeloRAT operators | A newer Python-based backdoor called ModeloRAT, deployed by the TAG-124 traffic distribution network tied to Interlock, further extends NodeSnake’s code structure and uses identical network validation bytes.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Node.js technique has been employed alongside ModeloRAT and Mistic, both assessed to be the work of the initial-access broker KongTuke/Woodgnat.
The Node.js technique has been employed alongside ModeloRAT and Mistic, both assessed to be the work of the initial-access broker KongTuke/Woodgnat.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
They hijack normal WordPress websites to push fake technical alerts. In a recent tactic from early 2026 called CrashFix, they purposely froze a victim’s web browser and displayed a message telling them to copy-paste a command to fix the issue.
“Eight command types give operators full remote code execution.”
Woodgnat attack chains abuse node.exe to execute attacker JavaScript and chain PowerShell and Windows command-line tools.
Woodgnat attack chains abuse node.exe to execute attacker JavaScript and chain PowerShell and Windows command-line tools.
Persistence is established through several redundant mechanisms, including... VBScript launchers
INTERPRETED_SCRIPT drops and runs another Python script with the bundled interpreter.
Attackers downloaded the official Node.js installer and used the trusted, signed node.exe runtime to execute attacker JavaScript and deploy a malicious implant.
That script, wrapped in stacked Base64 and XOR layers... ModeloRAT... builds C2 IP addresses through string concatenation... and ends with roughly 70 lines of junk code.
The extension copies a command to your clipboard disguised as edge.exe -fix-browser... Copy finger.exe out of System32 and rename it ct.exe to dodge name-based detection.
Delete the script so nothing is left on disk after it runs... Remove-Item "$env:APPDATA\script.ps1".
"...the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
“ModeloRAT is ... delivered only to domain-joined hosts in enterprise environments.”
The group then conducts extensive reconnaissance using built-in Windows tooling, enumerating domain users, groups, computers and sessions with net.exe
It checks running processes against a list of more than 50 analysis tools and VM indicators.
Then it reads the domain field from systeminfo and reports back with a marker, ABCD111 for standalone WORKGROUP hosts and BCDA222 for domain-joined ones.
It can also create new folders, and check for additional commands from the attacker-controlled command-and-control (C2) server.
“C2 traffic uses HTTP port 80 with RC4 encryption, zlib-compressed JSON, and adaptive beaconing intervals.”
"The malware was also distributed in a different ClickFix campaign that involved running commands carrying out a Domain Name System (DNS) lookup to retrieve the next-stage payload, with Microsoft noting that the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
For a domain-joined host, the C2 returns a command that grabs Winpython.zip, a Dropbox-hosted archive holding the portable WinPython build WPy64-31401, and starts the RAT with it.
"...the attack chain uses DNS as a 'lightweight staging or signaling channel.'"
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access tool observed in attacks abusing Node.js; believed to have been developed by the initial-access broker Woodgnat/KongTuke.
Remote-access malware associated in the report with KongTuke/Woodgnat attack activity leveraging Node.js and ClickFix.
Python-based Windows remote-access trojan delivered in the CrashFix campaign through a fake NexShield Chrome extension. It targets domain-joined enterprise hosts and uses HTTP over port 80 with RC4 encryption and zlib-compressed JSON for C2. Its eight command types support remote code execution, payload deployment, self-update, and implant termination.
Python-based Windows RAT delivered as the final payload in the CrashFix campaign. It uses a bundled portable Python runtime, maintains Run-key persistence, performs reconnaissance, executes arbitrary PowerShell commands, deploys EXE/DLL/Python payloads, updates itself, and supports clean termination. Its HTTP C2 uses RC4-encrypted, zlib-compressed JSON with adaptive beaconing.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.