logo

Help-Desk Lures Drop KongTuke's Evolved ModeloRAT

ID: 1b752e8c-794f-5521-a4a8-1c4eb01fa74b

STIX ID: report--1b752e8c-794f-5521-a4a8-1c4eb01fa74b

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-17

...
...

ReliaQuest attributes an active campaign to the initial access broker "KongTuke," which lures victims via external Microsoft Teams help-desk impersonation to paste a single PowerShell command that installs a portable WinPython runtime and ModeloRAT; the toolkit establishes persistence (four triggers) and three independent C2 paths, reaches persistent access in under five minutes, and uses rotating Microsoft 365 tenants and cloud-hosted ZIPs for delivery. The report provides IOCs, detailed execution and persistence artifacts (%APPDATA%\Roaming\WPy64-*, Run key, Startup shortcut, scriptA.vbs, SYSTEM scheduled task), and defensive recommendations including restricting Teams federation, hunting for portable Python in AppData, and auditing all persistence triggers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.