Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

Woodgnat

Also known as:KongTukeTAG-124LandUpdate808Chaya_002404 TDS

As of 2026-09-03, Woodgnat is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware. Also known as KongTuke, TAG-124, LandUpdate808, Chaya_002. ATT&CK coverage spans 82 techniques across 15 tactics in 5 of 5 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1041 (Exfiltration Over C2 Channel).

Tracked threats
51 critical · 4 high
First seen
2026-06-24
Last seen
2026-09-03
ATT&CK techniques
82across 5 of 5 threats
Related CVEs
0None referenced
5 tracked threat(s) · Categories: MALWARE

Activity timeline

Woodgnat appears in 5 tracked threats between and ; the busiest month was 2026-06 with 3 reports.

ATT&CK techniques observed

82 techniques observed across 5 of 5 tracked threats · Stealth (formerly Defense Evasion) (17), Command and Control (12), Execution (12), Credential Access (8), Discovery (8), Persistence (6)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 5 tracked threats
  • T1053.005 Scheduled Task — Persistenceobserved in 3 of 5 tracked threats
  • T1056.002 GUI Input Capture — Credential Accessobserved in 3 of 5 tracked threats
  • T1059.001 PowerShell — Executionobserved in 3 of 5 tracked threats
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1204.004 Malicious Copy and Paste — Executionobserved in 3 of 5 tracked threats
  • T1547.001 Registry Run Keys / Startup Folder — Persistenceobserved in 3 of 5 tracked threats
  • T1566 Phishing — Initial Accessobserved in 3 of 5 tracked threats
  • T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 2 of 5 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 2 of 5 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 5 tracked threats

Tracked threats