s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.modelorat

📛 Threat Title

Malware family: ModeloRAT

Category: ModeloRAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.modelorat`. Printable name: ModeloRAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:exchange.xforce.ibmcloud.com

    In April 2026, Rapid7 investigated a sophisticated enterprise intrusion that commenced with a deceptive Microsoft Teams message from a counterfeit 'IT Support' account. This incident rapidly escalated into a comprehensive compromise involving malware deployment, privilege escalation, credential theft, lateral movement, and data exfiltration. The attack underscored the growing risk posed by ...

  • web:malpedia.caad.fkie.fraunhofer.de

    ModeloRAT Propose Change According to Rapid7, ModeloRAT is a Python-based remote access trojan framework previously tied to the KongTuke group's browser extension campaigns, which in this incident was delivered through Microsoft Teams social engineering using a portable WinPython environment to bypass traditional detections.

  • web:malpedia.caad.fkie.fraunhofer.de

    This page gives an overview of all malware families that are covered on Malpedia, supplemented with some basic information for each family .

  • web:thehackernews.com

    Symantec and Carbon Black link Mistic backdoor attacks to KongTuke, using ClickFix lures and in-memory execution for stealthy access.

  • web:www.brightnexus.com

    The Mistic backdoor represents a new stealth-focused malware family linked to KongTuke and previously observed ModeloRAT activity. Through the use of ClickFix delivery mechanisms, DLL side-loading techniques, in-memory execution, and self-deletion capabilities, the malware provides operators with low-visibility access to compromised environments.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.security.com

    Stealthy new backdoor used in cybercrime intrusions since April 2026 may be associated with Woodgnat (aka KongTuke), an initial access broker whose ModeloRAT toolkit has fed Qilin and other ransomware operations.

  • web:www.securityweek.com

    Attackers are using DNS requests to deliver a RAT named ModeloRAT to targeted users. Microsoft has warned users that threat actors are leveraging a new variant of the ClickFix technique to deliver malware . The ClickFix attack method has been increasingly used in the past year by both cybercriminals ...

  • web:www.trendmicro.com

    Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.