logo

Threat Actors Use Hijacked Teams Accounts In ModeloRAT Attacks

ID: 6402b054-7a94-5715-a6a7-8d0492a4cc0c

STIX ID: report--6402b054-7a94-5715-a6a7-8d0492a4cc0c

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Varshini

...
...

KongTuke is running a sophisticated campaign that uses hijacked or fake Microsoft Teams accounts to convince employees to run an obfuscated PowerShell downloader that retrieves a ZIP from Dropbox. The archive deploys a portable Python runtime and an evolved ModeloRAT that splits reconnaissance and C2 functionality, implements persistence (hidden registry keys and scheduled tasks), and has reportedly evaded enterprise endpoint detection; organizations are advised to restrict Teams external access, block unnecessary Dropbox downloads, and hunt for hidden AppData ZIP extraction and related activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.