logo

KongTuke: A King Among Threat Groups

ID: 0c9820bf-4c0b-5e61-ae38-74476461a660

STIX ID: report--0c9820bf-4c0b-5e61-ae38-74476461a660

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-28

...
...

KongTuke, a FAKEUPDATES sub-group, compromises WordPress sites and serves obfuscated JavaScript that fingerprints visitors through a Traffic Distribution System (TDS) and selectively delivers malware via social-engineered prompts (fake Chrome updates and ClickFix clipboard commands). The campaign leverages stolen credentials or plugin misconfigurations for initial access, targets high-traffic domains across industries, uses persistent loaders and custom XOR+Gzip+zlib exfiltration, and is linked to multiple other malware and ransomware operators; notable indicators include endpoints like /land.php and /update.php and a consistent misspelling of the referer parameter as "refferer".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.