SEO Poisoning & NativeAOT: Unmasking the “Kong RAT” Campaign Targeting IT Professionals
ID: bc92e88a-a088-53ee-9c0c-9e8701e56c6d
STIX ID: report--bc92e88a-a088-53ee-9c0c-9e8701e56c6d
Feed Name: securityonline.info
Threat Score
**Executive summary:** Researchers uncovered the 'Kong RAT' campaign that used SEO poisoning to serve trojanized installers for popular Chinese-targeted networking and admin tools; the dropper was built with .NET 10.0 NativeAOT to hinder analysis, abused a LeTV geolocation API to fingerprint victims, and leveraged Alibaba Cloud OSS for payload/C2 hosting during an active campaign from May 2025 to March 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
