TF-1854628
medium
📛 Threat Title
KongTuke: Domain that is used for botnet Command&control (C&C) diranda.lol
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: KongTuke (aliases: TAG-124,js.LandUpdate808). Confidence: 50. First seen: 2026-07-21 05:20:55 UTC. Reporter: skocherhan. Tags: Kongtuke.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
diranda.lol
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/diranda.lol
UrlVoid 2 / 35
IOC database
- Type
- domain
- Value
diranda.lol- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain name that delivers a malware payload attributed to KongTuke
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/diranda.lol
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: KongTuke (aliases: TAG-124,js.LandUpdate808). Confidence: 50. First seen: 2026-07-20 23:55:34 UTC. Reporter: skocherhan. Tags: Kongtuke.
Remediations (10)
-
web:alpha-cyber.com
KongTuke is a recent, aggressive campaign that delivers a modified Interlock RAT (PHP variant) via a PyInstaller packed payload. This campaign shows how modern attackers chain packer evasion, malicious imports, and resilient C2 infrastructure to maintain persistence and extract value from victims.
-
web:aviatrix.ai
In November 2025, KongTuke used fake CAPTCHA lures and PowerShell to deploy persistent Python-based malware through compromised sites, evading detection.
-
web:boteraser.com
KongTuke achieves initial access through spear-phishing emails with malicious XLS or DOCM attachments that download a loader. The core DLL payload uses AES-encrypted configuration data and communicates over HTTPS to hardcoded C2 domains , employing domain -generation algorithms (DGAs) for backup.
-
web:isc.sans.edu
Shown above: Fake CAPTCHA page from a legitimate site with KongTuke -injected script, with the ClickFix style instructions and malicious command. The CAPTCHA page hijacks the clipboard, injecting text for a malicious command to download and run PowerShell script. Potential victims would read the instructions and paste this command into Run window.
-
web:redcanary.com
KongTuke (aka Chaya_002/LandUpdate808/TAG-124) is a traffic distribution system (TDS) that uses compromised WordPress sites to deploy malicious code. Traffic distribution systems are often used legitimately; they are platforms designed to filter and redirect network traffic, and were originally developed for use by digital advertisers.
-
web:reliaquest.com
Threat actors are impersonating help-desk staff over external Microsoft Teams chats to trick victims into deploying "ModeloRAT" on their own machines. ReliaQuest attributes the activity to financially motivated initial access broker (IAB) " KongTuke " based on reuse of the group's custom Python loader. Previously, KongTuke has compromised WordPress sites to host "ClickFix" and "CrashFix" lures ...
-
web:threatfox.abuse.ch
KongTuke IOC: diranda.lol ( domain ) You are viewing the ThreatFox database entry for domain diranda.lol .
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Overall botnet command control (C&C) activity decreased marginally by -4% between July and December last year. China dominated the Top 20 charts with increased botnet C&C activity across domain registrars and networks, ranking #1 globally for hosting botnet C&C servers. Download the latest report to learn more.
-
web:www.trendmicro.com
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.