PULSE NAME
IOC - Multi-Stage SEO Poisoning Campaign Targets Chinese-Speaking Developers with Kong RAT
WHITE celestre 2026-04-20 Modified: 2026-05-20
42
IOCs
MEDIUM VOLUME
In March 2026, eSentire's Threat Response Unit detected a sophisticated multi-stage malware campaign targeting Chinese-speaking developers and IT professionals through Search engine optimization (SEO) poisoning. Victims searching for popular Chinese developer tools including FinalShell SSH client, Xshell, QuickQ VPN, and Clash proxy, were redirected to convincing lookalike domains that delivered trojanized installers. TRU is tracking this threat as Kong RAT, named for its consistent use of the string "Kong" across registry keys/file paths used by the malware. The campaign's infrastructure consists of a network of spoofed Chinese software domains hosted on shared infrastructure, active from May 2025 through March 2026. Initial payloads were delivered via Alibaba Cloud Object Storage (Hong Kong region), and all stages consistently used oss-cn-hongkong.aliyuncs[.]com for payload hosting and C2 telemetry.
Indicators of Compromise (5 / 42 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4eb4e1ad917d85f9b52cac0946f1e6c4 MD5 of e16a79acf34a09d891e2d87bd8d1026b3f1310833cdcc6994557e8c277b678e2 2026-04-20
FileHash-MD5 8c050a38de18c80903c85e08213c8263 MD5 of 67a53570e6a84a90a174c4ee250e11fb64f13bafbf3c226830e442c158de7d21 2026-04-20
FileHash-MD5 ab6cf492d90ca87a4762f15678cceb86 MD5 of 17e800d967183db3d87b9baac4007a67dd17395efc94c05be92fe7a74423ad53 2026-04-20
FileHash-MD5 cf22f766a96d258accc64df518bf4527 MD5 of e718c89ce05a1e1b611f98d97cf8fed9b375741a0f7ad18bab39c62c721ab69a 2026-04-20
FileHash-MD5 df53c25243b31c85e00de026cf42bed9 MD5 of 736b2c5782fca75a85379181bcf1d3a719a14cacd938d053c03b16041059dd8f 2026-04-20