Hackers Spread Kong RAT Through Fake FinalShell and Xshell Download Sites
ID: 2205c0bf-1a94-5a29-b5c8-c226b4dde467
STIX ID: report--2205c0bf-1a94-5a29-b5c8-c226b4dde467
Feed Name: Cyber Press
Researchers uncovered a sustained SEO-poisoning campaign targeting Chinese-speaking developers that hosted polished fake download pages for FinalShell, Xshell, QuickQ and Clash to distribute trojanized installers containing Kong RAT. The malware uses a NativeAOT .NET first-stage, a custom TCP C2 protocol with LZ4 compression, and capabilities such as keylogging, remote command execution, plugin loading, and environment profiling; the report includes lookalike domains and operational details (Alibaba Cloud HK C2) as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
