TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

KongTuke Hackers Exploits Microsoft Teams To Breach Companies

Akinola Ajibola by Akinola Ajibola
May 14, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • KongTuke has been regarded as the original access broker and has switched to Microsoft Teams for social engineering attacks, which may obtain long-term access to corporate...
  • The ModeloRAT, which has previously been observed in ClickFix assaults, is finally delivered via the threat actor tricking users into pasting a PowerShell command [1, 2].
  • Ransomware operators usually purchase company network access from initial access brokers (IABs), such as KongTuke, and use it to spread malware of different kinds that encrypts...

KongTuke has been regarded as the original access broker and has switched to Microsoft Teams for social engineering attacks, which may obtain long-term access to corporate networks in as little as five minutes.

The ModeloRAT, which has previously been observed in ClickFix assaults, is finally delivered via the threat actor tricking users into pasting a PowerShell command [1, 2].

Ransomware operators usually purchase company network access from initial access brokers (IABs), such as KongTuke, and use it to spread malware of different kinds that encrypts data and steals user files.

Cybercriminals are increasingly using Microsoft Teams in their attacks, contacting company personnel while posing as the company’s IT and help desk personnel.

Even though the “ModeloRAT” malware is installed on the victims’ computers when they are persuaded to execute a malicious PowerShell command.

Sources from ReliaQuest experts claim that KongTuke used to just use web-based “FileFix” and “CrashFix” lures, and this behavior represents a change in strategy.

ReliaQuest further claims that this Teams activity is the first time we’ve seen KongTuke use a collaboration platform for initial access, and it seems to supplement rather than replace that web-based approach.

ReliaQuest shared illustrations of an incident that was looked into by the team where the operator went from cold outreach to a persistent foothold in less than five minutes with just one external Teams chat.

The researchers claimed that KongTuke has been running the operation since at least April 2026, switching between five Microsoft 365 tenants in order to avoid being blocked.

This act shows that the attacker employs Unicode whitespace trickery to make the display name seem authentic in order to pose as internal IT support personnel. 

ModeloRAT (Pmanager.py), a Python-based virus and also malware, is eventually launched by the malicious PowerShell command shared via Teams, which downloads a ZIP file from Dropbox that contains a portable WinPython environment.

In addition to taking images and exfiltrating files from the host drive, the virus gathers system and user data.

Also worth reading
Microsoft Teams Unveils Major Redesign Hackers Abuse Microsoft Password Reset to Steal Data Microsoft Confirms Degrading Service Outage On Teams Microsoft Retires Teams’ Together Mode to Simplify Video and Boost Performance Cybercriminal Twins Arrested After Leaving Microsoft Teams Recording On Microsoft: Teams Meeting Issues For Some Users After Edge Update

Based on ReliaQuest, there are three main ways in which the ModeloRAT version, which is used in this recent campaign, has changed from earlier operations:

A five-server pool, self-update capabilities, randomized URL pathways, and automatic failover make this C2 design stronger and more effective.

To maintain access in the event that one channel is broken, there are several independent access channels, such as a primary RAT, a reverse shell, and a TCP backdoor, operating on different infrastructure. 

Examples of expanded persistence mechanisms that could withstand typical cleanup methods are the Run keys, Startup shortcuts, VBScript launchers, and SYSTEM-level scheduled activities.

The researchers then observe that the implant’s self-destruct procedure, which erases the other persistence mechanisms and can endure and control the system reboots, does not delete the scheduled task.

It is then advised to use allowlists to limit the extent of the external Microsoft Teams federation in order to prevent Team-initiated attacks at the outset.

Furthermore, administrators can also search for attacks, indications of compromise, and persistence artifacts using the indicators of breach or compromise found in ReliaQuest’s report. 

Based on the ReliaQuest study, initial access brokers traditionally monetize their operations by selling persistent corporate network footholds to ransomware groups. Therefore, immediately addressing this exposure is a priority for organizations. IT administrators should apply the following baseline measures.

Firstly, the audit external connection policies in the Microsoft Teams admin centre. This will help restrict or eliminate open federated communication. Use strict allowlists to lock out external tenants by default.

Secondly, to  educate users never to act on technical instructions sent over collaborative message applications. Users should verify any such request through a secondary, corporate-approved platform. Examples include an official ticketing desk or a voice channel.

Thirdly, implement protective policies on client endpoints to restrict execution parameters for native scripting processes. Explicitly block command-line system configurations from processing untrusted internet inputs.

Related Reading

Explore more TechBooky stories from the latest and category sections below.

Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: hackersKongTukemicrosoft teamssecurity
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • New York’s Data Centre Pause Shows AI Infrastructure Is Hitting Politics July 23, 2026
  • OpenAI Researcher’s $2B Drug Discovery Plan Shows AI Biotech Hype Is Back July 23, 2026
  • Airtel Africa Q1 Shows Mobile Money And Data Are Doing The Heavy Lifting July 23, 2026
  • ZainTECH And Nile Build AI-Ready Networks For Enterprises July 23, 2026
  • Google Cloud Boom Makes Alphabet AI Spending Look More Real July 23, 2026
  • ServiceNow Says AI Is Helping Its Enterprise Software Story July 23, 2026
  • IBM Cuts Outlook As AI Spending Hits Its Mainframe Business July 23, 2026
  • Duplo And Wema Bank Bring Finance Automation To ALAT Businesses July 23, 2026
  • US Threatens Sanctions As Moonshot AI Kimi K3 Fight Escalates July 23, 2026
  • Alphabet Revenue Beats As Google Cloud And AI Spending Surge July 22, 2026
  • Tesla Revenue Beats But Profit Misses As AI Ambitions Raise Costs July 22, 2026
  • Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand July 22, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.