Skip to content

Kongtuke

KongTuke is a traffic distribution system and malware delivery framework first observed in 2024 that is primarily associated with compromised WordPress websites and ClickFix-style social engineering.

Profile source: Mallory opens in a new tab

Kongtuke

Family profile

KongTuke is a traffic distribution system and malware delivery framework first observed in 2024 that is primarily associated with compromised WordPress websites and ClickFix-style social engineering. It injects malicious JavaScript into legitimate sites, redirects visitors through staged infrastructure, and presents fake verification or CAPTCHA lures that coerce users into executing attacker-supplied commands. In 2025 and 2026, KongTuke activity was repeatedly linked to paste-and-run and FileFix variants, as well as to ClickFix chains that copied commands to the clipboard for manual execution on victim systems.

KongTuke has been used to deliver a range of downstream payloads, including loaders, remote access trojans, Node.js backdoors, stealers, and ransomware-associated tooling. Reported follow-on malware families include MintsLoader, GhostWeaver RAT, WARMCOOKIE, D3F@ck Loader, Mocha Manakin, Interlock, and Rhysida. Some observed chains also used DLL sideloading with legitimate signed Mozilla Firefox binaries, loading Rust-based malicious DLLs that acted as an initial loader, persistence component, and primary command-and-control implant.

The framework emphasizes resilient and flexible infrastructure. Observed campaigns used staged JavaScript delivery, gateway and clipboard handling, domain rotation, and in some cases blockchain-based retrieval of command-and-control configuration through Polygon smart contracts. Separate reporting also describes a domain generation algorithm used by KongTuke implants to derive command-and-control domains from themed wordlists and multiple top-level domains. Communications have been observed over HTTPS with regular beaconing behavior.

KongTuke is best understood as an initial-access and delivery ecosystem rather than a single monolithic payload. Its core function is to move victims from compromised web content or social-engineering lures into execution of additional malware, while supporting persistence and command-and-control in some variants. Activity associated with KongTuke has been tied to fake Cloudflare or browser-verification pages, fake CAPTCHA prompts, and compromised websites across broad victim populations rather than a single vertical. Reporting has also linked some KongTuke delivery chains to operations targeting Ukraine-related entities, although attribution remains campaign-specific rather than universally applicable to all KongTuke activity.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Initial Access
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
0 IP / 9 hostnames

Leading locations

  • US8

Leading providers

  • Cloudflare London, LLC5
  • Cloudflare, Inc.3

Infrastructure traits

  • Anycast 8
  • Hosting 8

MITRE ATT&CK

Kongtuke in ATT&CK

7 distinct techniques

Reporting

Research mentioning Kongtuke

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Jul 14
Derp Ca

From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io | Derp

Jul 14
Reddit Netsec

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist : r/netsec

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.