As cited
Citation snapshot as of .
ransomware
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
KongTuke, a financially motivated initial access broker, has shifted from web-based delivery methods to impersonating help-desk staff in external Microsoft Teams chats to distribute ModeloRAT, a remote access trojan with redundant command-and-control infrastructure and layered persistence mechanisms. The group achieves persistent access within five minutes of victims executing a single PowerShell command, and rotates through multiple Microsoft 365 tenants and persistence triggers to evade defensive measures. This represents the first known use of a collaboration platform by KongTuke for initial access and signals a broader trend of threat actors moving social engineering tactics from email and web vectors to Teams and similar platforms.
Why it matters: Security teams and Microsoft 365 administrators need to restrict external Teams federation and hunt for portable Python installations to detect KongTuke activity, as help-desk impersonation via Teams now represents a low-friction initial-access channel comparable to email that many organizations have not yet adequately controlled.
- Source published
- First seen by Cybersecurity Tracker