logo

KongTuke Abandoning “ClickFix” to Launch Direct Microsoft Teams Attacks

ID: 8189a252-45a9-5c71-892a-737694d79bc7

STIX ID: report--8189a252-45a9-5c71-892a-737694d79bc7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

ReliaQuest researchers attribute a fast, active initial access campaign to the financially motivated broker ‘KongTuke’, which has shifted from web-based lures to external Microsoft Teams chats to socially engineer victims into pasting a PowerShell command. The command drops a custom Python loader that installs ModeloRAT—a resilient RAT with three independent C2 paths and multiple persistence triggers—using a VBScript wrapper and a startup shortcut to achieve rapid, hard-to-contain footholds in enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.