Fake FinalShell and Xshell Sites Push Kong RAT Malware
ID: 842ce0e2-85ad-53e7-8a45-86780f24fd72
STIX ID: report--842ce0e2-85ad-53e7-8a45-86780f24fd72
Feed Name: GBHackers
A sophisticated SEO‑poisoning campaign targeting Chinese‑speaking developers and IT administrators impersonates FinalShell, Xshell, QuickQ, Clash and related tools to distribute a multi-stage Windows remote access trojan called Kong RAT. The operation uses trojanized installers (.NET NativeAOT dropper), reflective DLL loading, DLL sideloading, UAC bypass (CMSTPLUA and PEB masquerading), and RPC-based Task Scheduler persistence; Kong RAT implements a custom MPK1 LZ4-compressed C2 over TCP:5947, keylogging, AV enumeration, and remote-control capabilities. The report provides domains, Alibaba OSS download URLs, filesystem and scheduled-task indicators, and network characteristics defenders should monitor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
