logo

Fake FinalShell and Xshell Sites Push Kong RAT Malware

ID: 842ce0e2-85ad-53e7-8a45-86780f24fd72

STIX ID: report--842ce0e2-85ad-53e7-8a45-86780f24fd72

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Mayura Kathir

...
...

A sophisticated SEO‑poisoning campaign targeting Chinese‑speaking developers and IT administrators impersonates FinalShell, Xshell, QuickQ, Clash and related tools to distribute a multi-stage Windows remote access trojan called Kong RAT. The operation uses trojanized installers (.NET NativeAOT dropper), reflective DLL loading, DLL sideloading, UAC bypass (CMSTPLUA and PEB masquerading), and RPC-based Task Scheduler persistence; Kong RAT implements a custom MPK1 LZ4-compressed C2 over TCP:5947, keylogging, AV enumeration, and remote-control capabilities. The report provides domains, Alibaba OSS download URLs, filesystem and scheduled-task indicators, and network characteristics defenders should monitor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.