← Back to Feed
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
March 10, 2026 · Trend Micro · Severity: HIGH
Trend Micro's MDR team analyzes an active KongTuke campaign that deploys modeloRAT through compromised WordPress sites using fake CAPTCHA lures. The group continues operating this delivery chain in parallel with the newer CrashFix technique, targeting victims with remote access trojan capabilities.
Key Takeaways
- KongTuke continues deploying modeloRAT through compromised WordPress sites using fake CAPTCHA lures in active campaigns.
- The ClickFix technique delivers malware by tricking users into executing malicious commands under the guise of browser verification.
- modeloRAT provides full remote access including reconnaissance, command execution, and persistent backdoor capabilities.