logo

KongTuke activity, (Tue, Nov 18th)

ID: 6266e78b-54be-51f3-9c94-e0cfc55e1bb8

STIX ID: report--6266e78b-54be-51f3-9c94-e0cfc55e1bb8

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2025-11-18

Date Updated: 2026-04-19

...
...

This diary documents KongTuke (aka LandUpdate808/TAG-124) using fake CAPTCHA/ClickFix lures on compromised legitimate sites to socially engineer users into pasting a PowerShell command that downloads a ZIP with a malicious Python environment and script. The infection persists via a scheduled task, communicates with 64.111.92.212:6655 and telegra.ph, and leaves indicators in AppData\Roaming and scheduled tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.