PULSE NAME
IOC - Multi-Stage SEO Poisoning Campaign Targets Chinese-Speaking Developers with Kong RAT
WHITE celestre 2026-04-20 Modified: 2026-05-20
42
IOCs
MEDIUM VOLUME
In March 2026, eSentire's Threat Response Unit detected a sophisticated multi-stage malware campaign targeting Chinese-speaking developers and IT professionals through Search engine optimization (SEO) poisoning. Victims searching for popular Chinese developer tools including FinalShell SSH client, Xshell, QuickQ VPN, and Clash proxy, were redirected to convincing lookalike domains that delivered trojanized installers. TRU is tracking this threat as Kong RAT, named for its consistent use of the string "Kong" across registry keys/file paths used by the malware. The campaign's infrastructure consists of a network of spoofed Chinese software domains hosted on shared infrastructure, active from May 2025 through March 2026. Initial payloads were delivered via Alibaba Cloud Object Storage (Hong Kong region), and all stages consistently used oss-cn-hongkong.aliyuncs[.]com for payload hosting and C2 telemetry.
Indicators of Compromise (5 / 42 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0f28f95830ebad71e5fbfa0195a9674a7ac3c7d9 SHA1 of 67a53570e6a84a90a174c4ee250e11fb64f13bafbf3c226830e442c158de7d21 2026-04-20
FileHash-SHA1 12d0556525077f1e6bd69ced9bb7358c223dee73 SHA1 of e16a79acf34a09d891e2d87bd8d1026b3f1310833cdcc6994557e8c277b678e2 2026-04-20
FileHash-SHA1 3e2a5236ad9f33782eb1b350674fe215e7b53ca1 SHA1 of e718c89ce05a1e1b611f98d97cf8fed9b375741a0f7ad18bab39c62c721ab69a 2026-04-20
FileHash-SHA1 5ff5c29a8c4ce32bb757dcfe43670f44fa148a34 SHA1 of 736b2c5782fca75a85379181bcf1d3a719a14cacd938d053c03b16041059dd8f 2026-04-20
FileHash-SHA1 6c609755f92e9d21985211a2e3960a3dea62dbe8 SHA1 of 17e800d967183db3d87b9baac4007a67dd17395efc94c05be92fe7a74423ad53 2026-04-20