s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1854628 medium

📛 Threat Title

KongTuke: Domain that is used for botnet Command&control (C&C) diranda.lol

Category: KongTuke Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: KongTuke (aliases: TAG-124,js.LandUpdate808). Confidence: 50. First seen: 2026-07-21 05:20:55 UTC. Reporter: skocherhan. Tags: Kongtuke.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain diranda.lol VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/diranda.lol
UrlVoid 2 / 35

IOC database

Type
domain
Value
diranda.lol
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Domain name that delivers a malware payload attributed to KongTuke

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/diranda.lol

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: KongTuke (aliases: TAG-124,js.LandUpdate808). Confidence: 50. First seen: 2026-07-20 23:55:34 UTC. Reporter: skocherhan. Tags: Kongtuke.

Remediations (10)

  • web:alpha-cyber.com

    KongTuke is a recent, aggressive campaign that delivers a modified Interlock RAT (PHP variant) via a PyInstaller packed payload. This campaign shows how modern attackers chain packer evasion, malicious imports, and resilient C2 infrastructure to maintain persistence and extract value from victims.

  • web:aviatrix.ai

    In November 2025, KongTuke used fake CAPTCHA lures and PowerShell to deploy persistent Python-based malware through compromised sites, evading detection.

  • web:boteraser.com

    KongTuke achieves initial access through spear-phishing emails with malicious XLS or DOCM attachments that download a loader. The core DLL payload uses AES-encrypted configuration data and communicates over HTTPS to hardcoded C2 domains , employing domain -generation algorithms (DGAs) for backup.

  • web:isc.sans.edu

    Shown above: Fake CAPTCHA page from a legitimate site with KongTuke -injected script, with the ClickFix style instructions and malicious command. The CAPTCHA page hijacks the clipboard, injecting text for a malicious command to download and run PowerShell script. Potential victims would read the instructions and paste this command into Run window.

  • web:redcanary.com

    KongTuke (aka Chaya_002/LandUpdate808/TAG-124) is a traffic distribution system (TDS) that uses compromised WordPress sites to deploy malicious code. Traffic distribution systems are often used legitimately; they are platforms designed to filter and redirect network traffic, and were originally developed for use by digital advertisers.

  • web:reliaquest.com

    Threat actors are impersonating help-desk staff over external Microsoft Teams chats to trick victims into deploying "ModeloRAT" on their own machines. ReliaQuest attributes the activity to financially motivated initial access broker (IAB) " KongTuke " based on reuse of the group's custom Python loader. Previously, KongTuke has compromised WordPress sites to host "ClickFix" and "CrashFix" lures ...

  • web:threatfox.abuse.ch

    KongTuke IOC: diranda.lol ( domain ) You are viewing the ThreatFox database entry for domain diranda.lol .

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    Overall botnet command control (C&C) activity decreased marginally by -4% between July and December last year. China dominated the Top 20 charts with increased botnet C&C activity across domain registrars and networks, ranking #1 globally for hosting botnet C&C servers. Download the latest report to learn more.

  • web:www.trendmicro.com

    Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.