KongTuke activity, (Tue, Nov 18th)
ID: 6266e78b-54be-51f3-9c94-e0cfc55e1bb8
STIX ID: report--6266e78b-54be-51f3-9c94-e0cfc55e1bb8
Feed Name: SANS ISC Diary
Threat Score
This diary documents KongTuke (aka LandUpdate808/TAG-124) using fake CAPTCHA/ClickFix lures on compromised legitimate sites to socially engineer users into pasting a PowerShell command that downloads a ZIP with a malicious Python environment and script. The infection persists via a scheduled task, communicates with 64.111.92.212:6655 and telegra.ph, and leaves indicators in AppData\Roaming and scheduled tasks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
