Resources & Insights
Lisa Wu
2 articles
-
BlogThrough the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT — malware capable of reconnaissance, command execution, and persistent access — through compromised WordPress sites and fake CAPTCHA lures shows that the group still operates this delivery chain in parallel with the newer CrashFix technique.
March 10th, 2026 9 minAira Marcelo, Jovit Samaniego, Ryan Maglaque, Fe Cureg…
Read article -
BlogFake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
We have detected a new tactic involving fake CAPTCHA pages that trick users into executing harmful commands in Windows. This scheme uses disguised files sent via phishing and other malicious methods.
May 19th, 2025 15 minBuddy Tancio, Khristoffer Jocson, Maylein Tom, Lisa Wu…
Read article