KongTuke Abandoning “ClickFix” to Launch Direct Microsoft Teams Attacks
ID: 8189a252-45a9-5c71-892a-737694d79bc7
STIX ID: report--8189a252-45a9-5c71-892a-737694d79bc7
Feed Name: securityonline.info
ReliaQuest researchers attribute a fast, active initial access campaign to the financially motivated broker ‘KongTuke’, which has shifted from web-based lures to external Microsoft Teams chats to socially engineer victims into pasting a PowerShell command. The command drops a custom Python loader that installs ModeloRAT—a resilient RAT with three independent C2 paths and multiple persistence triggers—using a VBScript wrapper and a startup shortcut to achieve rapid, hard-to-contain footholds in enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
