KongTuke Campaign Exploits Compromised WordPress Sites with modeloRAT
First seen 10 Mar 2026, 12:54 UTC
•
•100% similarity
•51.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The KongTuke group is actively deploying modeloRAT malware through compromised WordPress sites, utilizing fake CAPTCHA lures for initial access. This campaign continues alongside their newer CrashFix technique, posing a significant threat to affected organizations relying on WordPress. Huntress researchers identified this tactic in January 2026.
ThreatCluster AI
How this analysis works
Timeline
2026-01-01
Huntress identifies new initial access technique by KongTuke
2026-03-10
Trendmicro publishes analysis of KongTuke's ClickFix abuse