← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - Multi-Stage SEO Poisoning Campaign Targets Chinese-Speaking Developers with Kong RAT
In March 2026, eSentire's Threat Response Unit detected a sophisticated multi-stage malware campaign targeting Chinese-speaking developers and IT professionals through Search engine optimization (SEO) poisoning. Victims searching for popular Chinese developer tools including FinalShell SSH client, Xshell, QuickQ VPN, and Clash proxy, were redirected to convincing lookalike domains that delivered trojanized installers. TRU is tracking this threat as Kong RAT, named for its consistent use of the string "Kong" across registry keys/file paths used by the malware. The campaign's infrastructure consists of a network of spoofed Chinese software domains hosted on shared infrastructure, active from May 2025 through March 2026. Initial payloads were delivered via Alibaba Cloud Object Storage (Hong Kong region), and all stages consistently used oss-cn-hongkong.aliyuncs[.]com for payload hosting and C2 telemetry.
Indicators of Compromise (5 / 42 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 0f28f95830ebad71e5fbfa0195a9674a7ac3c7d9 | SHA1 of 67a53570e6a84a90a174c4ee250e11fb64f13bafbf3c226830e442c158de7d21 | 2026-04-20 | |
| FileHash-SHA1 | 12d0556525077f1e6bd69ced9bb7358c223dee73 | SHA1 of e16a79acf34a09d891e2d87bd8d1026b3f1310833cdcc6994557e8c277b678e2 | 2026-04-20 | |
| FileHash-SHA1 | 3e2a5236ad9f33782eb1b350674fe215e7b53ca1 | SHA1 of e718c89ce05a1e1b611f98d97cf8fed9b375741a0f7ad18bab39c62c721ab69a | 2026-04-20 | |
| FileHash-SHA1 | 5ff5c29a8c4ce32bb757dcfe43670f44fa148a34 | SHA1 of 736b2c5782fca75a85379181bcf1d3a719a14cacd938d053c03b16041059dd8f | 2026-04-20 | |
| FileHash-SHA1 | 6c609755f92e9d21985211a2e3960a3dea62dbe8 | SHA1 of 17e800d967183db3d87b9baac4007a67dd17395efc94c05be92fe7a74423ad53 | 2026-04-20 |