logo

KongTuke hackers now use Microsoft Teams for corporate breaches

ID: 5f7fa9fd-b891-525e-b517-06a491cabf40

STIX ID: report--5f7fa9fd-b891-525e-b517-06a491cabf40

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Bill Toulas

...
...

ReliaQuest observed initial access broker KongTuke leveraging Microsoft Teams to socially engineer employees into pasting a PowerShell command that downloads a ZIP containing a portable WinPython environment which launches ModeloRAT (Pmanager.py). The campaign (active since at least April 2026) features tenant rotation to evade blocking, Unicode tricks to impersonate IT staff, a resilient five-server C2 pool with failover and self-update, multiple independent access paths (RAT, reverse shell, TCP backdoor), and expanded persistence (Run keys, startup shortcuts, VBScript launchers, and SYSTEM-level scheduled tasks). ModeloRAT collects system/user data, screenshots, and can exfiltrate files; defenders are advised to restrict external Teams federation, apply allowlists, and hunt for the provided IoCs and persistence artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.