# Woodgnat

> As of 2026-09-03, Woodgnat is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware. Also known as KongTuke, TAG-124, LandUpdate808, Chaya_002. ATT&CK coverage spans 82 techniques across 15 tactics in 5 of 5 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 5
- **Categories:** MALWARE
- **Also known as:** KongTuke, TAG-124, LandUpdate808, Chaya_002, 404 TDS
- **As of:** 2026-09-03

## ATT&CK techniques observed

82 techniques observed across 5 of 5 tracked threats. Tactics: Stealth (formerly Defense Evasion) (17), Command and Control (12), Execution (12), Credential Access (8), Discovery (8), Persistence (6).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 5 tracked threats
- [T1053.005](https://intel.threadlinqs.com/technique/T1053.005) Scheduled Task — Persistence — observed in 3 of 5 tracked threats
- [T1056.002](https://intel.threadlinqs.com/technique/T1056.002) GUI Input Capture — Credential Access — observed in 3 of 5 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 3 of 5 tracked threats
- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1204.004](https://intel.threadlinqs.com/technique/T1204.004) Malicious Copy and Paste — Execution — observed in 3 of 5 tracked threats
- [T1547.001](https://intel.threadlinqs.com/technique/T1547.001) Registry Run Keys / Startup Folder — Persistence — observed in 3 of 5 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 3 of 5 tracked threats
- [T1574.001](https://intel.threadlinqs.com/technique/T1574.001) DLL — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 5 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 5 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 5 tracked threats

## Tracked threats

- [Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers](https://intel.threadlinqs.com/threat/TL-2026-2304) — HIGH
- [Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading — Woodgnat/KongTuke Access Broker](https://intel.threadlinqs.com/threat/TL-2026-1038) — HIGH
- [Mistic Windows Backdoor - In-Memory Code Execution via DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-1017) — CRITICAL
- [Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Broker](https://intel.threadlinqs.com/threat/TL-2026-2277) — HIGH
- [Backdoor.Mistic (MLTBackdoor) — In-Memory BOF-Capable Backdoor Deployed by Woodgnat/KongTuke IAB Alongside ModeloRAT](https://intel.threadlinqs.com/threat/TL-2026-0933) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Woodgnat
