CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Help-Desk Lures Drop KongTuke's Evolved ModeloRAT

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 2116

As cited

Citation snapshot as of .

ransomware

Help-Desk Lures Drop KongTuke's Evolved ModeloRAT

KongTuke, a financially motivated initial access broker, has shifted from web-based delivery methods to impersonating help-desk staff in external Microsoft Teams chats to distribute ModeloRAT, a remote access trojan with redundant command-and-control infrastructure and layered persistence mechanisms. The group achieves persistent access within five minutes of victims executing a single PowerShell command, and rotates through multiple Microsoft 365 tenants and persistence triggers to evade defensive measures. This represents the first known use of a collaboration platform by KongTuke for initial access and signals a broader trend of threat actors moving social engineering tactics from email and web vectors to Teams and similar platforms.

Why it matters: Security teams and Microsoft 365 administrators need to restrict external Teams federation and hunt for portable Python installations to detect KongTuke activity, as help-desk impersonation via Teams now represents a low-friction initial-access channel comparable to email that many organizations have not yet adequately controlled.

Source published
First seen by Cybersecurity Tracker

Source attribution