Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 8, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 21 hostnames
KongTuke is a malicious traffic distribution system active since at least 2024 that compromises legitimate WordPress sites and injects JavaScript to redirect visitors into malware delivery chains.
Profile source: Mallory opens in a new tabKongtuke
KongTuke is a malicious traffic distribution system active since at least 2024 that compromises legitimate WordPress sites and injects JavaScript to redirect visitors into malware delivery chains. It is also tracked under aliases including 404 TDS, Chaya_002, LandUpdate808, TAG-124, and js.kongtuke. Rather than being a single end-stage payload, KongTuke functions as an intermediary delivery framework that profiles victims, routes traffic, and presents social-engineering lures that lead users to execute attacker-supplied commands or retrieve additional malware.
Observed KongTuke activity heavily relies on ClickFix and related paste-and-run techniques, including fake CAPTCHA and FileFix variants. Victims visiting compromised websites are shown verification-style prompts that covertly place commands in the clipboard and instruct the user to paste and run them through Windows interfaces. KongTuke has also been observed using injected scripts on compromised sites to stage multi-step delivery flows involving tokening, gateway logic, clipboard manipulation, and subsequent payload download.
The infrastructure and delivery logic are designed for resilience and evasion. In one documented variant, the malicious JavaScript retrieved command-and-control configuration dynamically from a Polygon blockchain smart contract instead of hardcoding infrastructure, enabling rapid backend rotation and complicating static detection. KongTuke has been associated with fake Cloudflare-style verification pages and other browser-verification lures intended to make the interaction appear legitimate.
KongTuke has been linked to delivery of multiple downstream malware families, including MintsLoader, WARMCOOKIE, D3F@ck Loader, Mocha Manakin, Node.js backdoors, remote-access tooling, and ransomware such as Rhysida and Interlock. Reported follow-on payload behavior has included host profiling, remote access, tunneling through SOCKS5 proxies, scheduled-task persistence, and staged archive delivery. KongTuke delivery chains have also overlapped with activity involving GREYVIBE, and some reporting attributes the broader TDS activity to clusters tracked as TAG-124.
The malware primarily targets Windows users through browser-based social engineering delivered from compromised WordPress sites. Its role in the intrusion lifecycle is initial access and payload delivery, with strong emphasis on defense evasion through dynamic infrastructure, compromised legitimate websites, and user-assisted execution.
MITRE ATT&CK
Reporting
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.