logo

Hackers Spread Kong RAT Through Fake FinalShell and Xshell Download Sites

ID: 2205c0bf-1a94-5a29-b5c8-c226b4dde467

STIX ID: report--2205c0bf-1a94-5a29-b5c8-c226b4dde467

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Varshini

...
...

Researchers uncovered a sustained SEO-poisoning campaign targeting Chinese-speaking developers that hosted polished fake download pages for FinalShell, Xshell, QuickQ and Clash to distribute trojanized installers containing Kong RAT. The malware uses a NativeAOT .NET first-stage, a custom TCP C2 protocol with LZ4 compression, and capabilities such as keylogging, remote command execution, plugin loading, and environment profiling; the report includes lookalike domains and operational details (Alibaba Cloud HK C2) as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.