KongTuke Campaign Exploits Compromised WordPress Sites with modeloRAT

KongTuke Campaign Exploits Compromised WordPress Sites with modeloRAT

First seen 10 Mar 2026, 12:54 UTC Feeds.TrendmicroTrendmicro 100% similarity 51.9

Article Content

Browse articles
ThreatCluster

The KongTuke group is actively deploying modeloRAT malware through compromised WordPress sites, utilizing fake CAPTCHA lures for initial access. This campaign continues alongside their newer CrashFix technique, posing a significant threat to affected organizations relying on WordPress. Huntress researchers identified this tactic in January 2026.

ThreatCluster AI How this analysis works

Timeline

2026-01-01
Huntress identifies new initial access technique by KongTuke
2026-03-10
Trendmicro publishes analysis of KongTuke's ClickFix abuse

Community

Browse all →