logo

SEO Poisoning & NativeAOT: Unmasking the “Kong RAT” Campaign Targeting IT Professionals

ID: bc92e88a-a088-53ee-9c0c-9e8701e56c6d

STIX ID: report--bc92e88a-a088-53ee-9c0c-9e8701e56c6d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** Researchers uncovered the 'Kong RAT' campaign that used SEO poisoning to serve trojanized installers for popular Chinese-targeted networking and admin tools; the dropper was built with .NET 10.0 NativeAOT to hinder analysis, abused a LeTV geolocation API to fingerprint victims, and leveraged Alibaba Cloud OSS for payload/C2 hosting during an active campaign from May 2025 to March 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.