Initial access broker KongTuke has expanded its attack methods to include Microsoft Teams, using social engineering to trick corporate employees into running malicious PowerShell commands. The attack chain downloads a ZIP from Dropbox containing a portable WinPython environment that deploys ModeloRAT, a Python-based remote access trojan. The updated ModeloRAT features a resilient five-server C2 pool with automatic failover, multiple independent access paths (RAT, reverse shell, TCP backdoor), and expanded persistence mechanisms including Run keys, Startup shortcuts, VBScript launchers, and SYSTEM-level scheduled tasks that survive cleanup. KongTuke rotates through five Microsoft 365 tenants to evade blocking and uses Unicode whitespace tricks to impersonate IT support staff. The entire compromise can take under five minutes. Defenders are advised to restrict external Teams federation via allowlists and monitor indicators of compromise published by ReliaQuest.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
83 Impressions