Activity timeline
KongTuke appears in 5 tracked threats between and ; the busiest month was 2026-06 with 2 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 5 of 5 tracked threats
- T1497 Virtualization/Sandbox Evasion — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
- T1016 System Network Configuration Discovery — Discoveryobserved in 4 of 5 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 5 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
- T1057 Process Discovery — Discoveryobserved in 3 of 5 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 5 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 5 tracked threats
- T1189 Drive-by Compromise — Initial Accessobserved in 3 of 5 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 3 of 5 tracked threats
- T1204 User Execution — Executionobserved in 3 of 5 tracked threats
- T1218 System Binary Proxy Execution — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
- T1518 Software Discovery — Discoveryobserved in 3 of 5 tracked threats
Tracked threats
- MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL SideloadingHIGH
- Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware IntrusionsHIGH
- Backdoor.Mistic (MLTBackdoor) — In-Memory BOF-Capable Backdoor Deployed by Woodgnat/KongTuke IAB Alongside ModeloRATHIGH
- KongTuke ClickFix Campaign — ModeloRAT Deployment via Compromised WordPress Sites and CrashFix Browser ExtensionHIGH
- ClickFix Evolution — nslookup DNS Smuggling + CrashFix Browser DoS + ModeloRAT Python RAT, KongTuke Actor, Enterprise Domain-Joined TargetingHIGH