logo

KongTuke on compromised WordPress sites, DDOS Botnets and Cybercriminal Feuds

ID: 9664e24f-3026-58f3-babd-0bdafa4bffa7

STIX ID: report--9664e24f-3026-58f3-babd-0bdafa4bffa7

Feed Name: Ctrl-Alt-Int3l

Threat Score
72/100

Date Published: 2026-04-22

Date Updated: 2026-05-05

Author: Ctrl-Alt-Intel

...
...

Ctrl-Alt-Intel discovered an unauthenticated C2 panel (107.158.128.79) exposing 219 compromised web servers and 4,229 commands; the operator used these WordPress compromises to deploy a malicious plugin (z.php) that staged ClickFix/KongTuke JavaScript (windlrr.com / nitzschi.com), enrolled sites into a Mirai-variant botnet via a downloader (ohshit.sh from 45.141.26.73), and directed mass HTTP-floods against government and rival cybercrime sites; the report includes full command logs, victim metadata (including TGI Fridays), IOCs, and ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.