TF-MAL-py.modelorat
📛 Threat Title
Malware family: ModeloRAT
Description
ThreatFox malware family `py.modelorat`. Printable name: ModeloRAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.
-
web:exchange.xforce.ibmcloud.com
In April 2026, Rapid7 investigated a sophisticated enterprise intrusion that commenced with a deceptive Microsoft Teams message from a counterfeit 'IT Support' account. This incident rapidly escalated into a comprehensive compromise involving malware deployment, privilege escalation, credential theft, lateral movement, and data exfiltration. The attack underscored the growing risk posed by ...
-
web:malpedia.caad.fkie.fraunhofer.de
ModeloRAT Propose Change According to Rapid7, ModeloRAT is a Python-based remote access trojan framework previously tied to the KongTuke group's browser extension campaigns, which in this incident was delivered through Microsoft Teams social engineering using a portable WinPython environment to bypass traditional detections.
-
web:malpedia.caad.fkie.fraunhofer.de
This page gives an overview of all malware families that are covered on Malpedia, supplemented with some basic information for each family .
-
web:thehackernews.com
Symantec and Carbon Black link Mistic backdoor attacks to KongTuke, using ClickFix lures and in-memory execution for stealthy access.
-
web:www.brightnexus.com
The Mistic backdoor represents a new stealth-focused malware family linked to KongTuke and previously observed ModeloRAT activity. Through the use of ClickFix delivery mechanisms, DLL side-loading techniques, in-memory execution, and self-deletion capabilities, the malware provides operators with low-visibility access to compromised environments.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.security.com
Stealthy new backdoor used in cybercrime intrusions since April 2026 may be associated with Woodgnat (aka KongTuke), an initial access broker whose ModeloRAT toolkit has fed Qilin and other ransomware operations.
-
web:www.securityweek.com
Attackers are using DNS requests to deliver a RAT named ModeloRAT to targeted users. Microsoft has warned users that threat actors are leveraging a new variant of the ClickFix technique to deliver malware . The ClickFix attack method has been increasingly used in the past year by both cybercriminals ...
-
web:www.trendmicro.com
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.