The KongTuke threat cluster is using Microsoft Teams to breach corporate environments by impersonating internal IT or help-desk staff through fake or hijacked accounts. In observed intrusions, attackers convince employees to paste an obfuscated PowerShell command that retrieves a ZIP archive from Dropbox, leading to deployment of the Python-based ModeloRAT malware. Researchers said the operation can establish persistent access in under five minutes and has used rotating Microsoft 365 tenants plus Unicode whitespace in display names to make attacker-controlled accounts appear legitimate inside Teams conversations.
The updated ModeloRAT variant unpacks a portable WinPython environment in user directories, including AppData and the WPy64-31401 folder, then separates reconnaissance from command-and-control activity while adding stronger evasion and persistence. Reports said the malware had zero detections on VirusTotal at the time of analysis, bypassed several EDR tools, and maintained access through Windows Run registry keys, randomly named scheduled tasks, and in some cases a SYSTEM-level scheduled task that may survive cleanup and reboots. Defenders were urged to restrict or allowlist external Teams federation, monitor Dropbox downloads and ZIP extraction in AppData, detect pythonw.exe launched from user-writable paths, and review new scheduled tasks and registry changes for persistence artifacts.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On May 14, 2026, reporting based on ReliaQuest research publicly detailed that KongTuke was using fake or hijacked Microsoft Teams accounts, rotating Microsoft 365 tenants, and Unicode whitespace tricks in display names to make messages appear legitimate. The disclosure also noted that attackers could gain persistent access to corporate networks in under five minutes and included indicators of compromise and mitigation guidance.
By May 2026, researchers observed a new ModeloRAT infection chain in which victims paste an obfuscated PowerShell command that downloads a ZIP archive from Dropbox, unpacks a portable WinPython environment in AppData, and launches the malware. The updated variant added stronger evasion, redundant command-and-control and persistence mechanisms, including Run registry keys and randomly named or SYSTEM-level scheduled tasks.
ReliaQuest reported that the KongTuke threat cluster had been using Microsoft Teams since at least April 2026 to impersonate internal IT or help-desk staff and socially engineer employees into running malicious commands. The activity marked the first observed use of a collaboration platform by KongTuke for initial access, expanding beyond its earlier web-based lures.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.