← Back to Feed

Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites

March 10, 2026 · Trend Micro · Severity: HIGH

Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.

Key Takeaways

  • KongTuke uses compromised WordPress sites and fake CAPTCHA lures to deploy modeloRAT.
  • ModeloRAT is capable of reconnaissance, command execution, and persistent access.
  • The group operates this delivery chain in parallel with the newer CrashFix technique.
☕ Buy a Coffee