Skip to content

Kongtuke

KongTuke is a malicious traffic distribution system active since at least 2024 that compromises legitimate WordPress sites and injects JavaScript to redirect visitors into malware delivery chains.

Profile source: Mallory opens in a new tab

Kongtuke

Family profile

KongTuke is a malicious traffic distribution system active since at least 2024 that compromises legitimate WordPress sites and injects JavaScript to redirect visitors into malware delivery chains. It is also tracked under aliases including 404 TDS, Chaya_002, LandUpdate808, TAG-124, and js.kongtuke. Rather than being a single end-stage payload, KongTuke functions as an intermediary delivery framework that profiles victims, routes traffic, and presents social-engineering lures that lead users to execute attacker-supplied commands or retrieve additional malware.

Observed KongTuke activity heavily relies on ClickFix and related paste-and-run techniques, including fake CAPTCHA and FileFix variants. Victims visiting compromised websites are shown verification-style prompts that covertly place commands in the clipboard and instruct the user to paste and run them through Windows interfaces. KongTuke has also been observed using injected scripts on compromised sites to stage multi-step delivery flows involving tokening, gateway logic, clipboard manipulation, and subsequent payload download.

The infrastructure and delivery logic are designed for resilience and evasion. In one documented variant, the malicious JavaScript retrieved command-and-control configuration dynamically from a Polygon blockchain smart contract instead of hardcoding infrastructure, enabling rapid backend rotation and complicating static detection. KongTuke has been associated with fake Cloudflare-style verification pages and other browser-verification lures intended to make the interaction appear legitimate.

KongTuke has been linked to delivery of multiple downstream malware families, including MintsLoader, WARMCOOKIE, D3F@ck Loader, Mocha Manakin, Node.js backdoors, remote-access tooling, and ransomware such as Rhysida and Interlock. Reported follow-on payload behavior has included host profiling, remote access, tunneling through SOCKS5 proxies, scheduled-task persistence, and staged archive delivery. KongTuke delivery chains have also overlapped with activity involving GREYVIBE, and some reporting attributes the broader TDS activity to clusters tracked as TAG-124.

The malware primarily targets Windows users through browser-based social engineering delivered from compromised WordPress sites. Its role in the intrusion lifecycle is initial access and payload delivery, with strong emphasis on defense evasion through dynamic infrastructure, compromised legitimate websites, and user-assisted execution.

Capabilities

  • Defense Evasion
  • Initial Access
  • Reconnaissance

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 8, 2026
Feed role
Distribution
Host form
0 IP / 21 hostnames

Leading locations

  • US20
  • AU1

Leading providers

  • Cloudflare London, LLC12
  • Cloudflare, Inc.4
  • Google LLC1
  • Internap Holding LLC1
  • Jeanneret Electrical Technologies P/L1
  • Liquid Web, L.L.C1

Infrastructure traits

  • Hosting 20
  • Anycast 16
  • Proxy 13

MITRE ATT&CK

Kongtuke in ATT&CK

5 distinct techniques

Reporting

Research mentioning Kongtuke

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Jul 14
Derp Ca

From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io | Derp

Jul 14
Reddit Netsec

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist : r/netsec

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.