Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 9 hostnames
KongTuke is a traffic distribution system and malware delivery framework first observed in 2024 that is primarily associated with compromised WordPress websites and ClickFix-style social engineering.
Profile source: Mallory opens in a new tabKongtuke
KongTuke is a traffic distribution system and malware delivery framework first observed in 2024 that is primarily associated with compromised WordPress websites and ClickFix-style social engineering. It injects malicious JavaScript into legitimate sites, redirects visitors through staged infrastructure, and presents fake verification or CAPTCHA lures that coerce users into executing attacker-supplied commands. In 2025 and 2026, KongTuke activity was repeatedly linked to paste-and-run and FileFix variants, as well as to ClickFix chains that copied commands to the clipboard for manual execution on victim systems.
KongTuke has been used to deliver a range of downstream payloads, including loaders, remote access trojans, Node.js backdoors, stealers, and ransomware-associated tooling. Reported follow-on malware families include MintsLoader, GhostWeaver RAT, WARMCOOKIE, D3F@ck Loader, Mocha Manakin, Interlock, and Rhysida. Some observed chains also used DLL sideloading with legitimate signed Mozilla Firefox binaries, loading Rust-based malicious DLLs that acted as an initial loader, persistence component, and primary command-and-control implant.
The framework emphasizes resilient and flexible infrastructure. Observed campaigns used staged JavaScript delivery, gateway and clipboard handling, domain rotation, and in some cases blockchain-based retrieval of command-and-control configuration through Polygon smart contracts. Separate reporting also describes a domain generation algorithm used by KongTuke implants to derive command-and-control domains from themed wordlists and multiple top-level domains. Communications have been observed over HTTPS with regular beaconing behavior.
KongTuke is best understood as an initial-access and delivery ecosystem rather than a single monolithic payload. Its core function is to move victims from compromised web content or social-engineering lures into execution of additional malware, while supporting persistence and command-and-control in some variants. Activity associated with KongTuke has been tied to fake Cloudflare or browser-verification pages, fake CAPTCHA prompts, and compromised websites across broad victim populations rather than a single vertical. Reporting has also linked some KongTuke delivery chains to operations targeting Ukraine-related entities, although attribution remains campaign-specific rather than universally applicable to all KongTuke activity.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Reporting
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.