← Back to Feed
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
March 10, 2026 · Trend Micro · Severity: HIGH
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
Key Takeaways
- An active KongTuke campaign deploys modeloRAT through compromised WordPress sites and fake CAPTCHA lures, according to Trend Micro MDR analysis.
- modeloRAT is capable of reconnaissance, command execution, and persistent access, and the group runs this chain alongside newer CrashFix techniques.
- Organizations should patch WordPress plugins and train users to recognize fake CAPTCHA prompts that deliver malware.