TAG-124, KongTuke, LandUpdate808, and Chaya_002
Navigate overlapping labels for a modular compromised-WordPress delivery ecosystem.
In this lesson, you will learn to:
- Describe the TAG-124 layered architecture.
- Handle KongTuke and related aliases with explicit source scope.
TAG-124, KongTuke, LandUpdate808, and Chaya_002
Uses 2024–2026 research to connect injected sites, device checks, cookie gates, fake updates, fake CAPTCHA or ClickFix lures, payload servers, and overlapping vendor names.
The cluster is layered
Recorded Future described TAG-124 infrastructure observed in 2024 as a network of compromised WordPress sites, actor-controlled payload servers, a central command server, and other supporting components. Virus Bulletin’s 2025 research said TAG-124 overlaps with LandUpdate808, KongTuke, and Chaya_002 and described modular logic that collected device and operating-system data, checked cookies, and selected a fake Chrome update or fake CAPTCHA/ClickFix landing page.
These names are useful for correlating research, but avoid writing “all four names always mean exactly the same operator.” Record which source made the mapping and which layer it studied. Red Canary describes KongTuke as a malicious TDS using compromised WordPress sites to deploy changing lures. The shared core is a defensible behavioral model even where naming boundaries differ.
Lures rotate while the funnel persists
The user may see a fake browser update, fake CAPTCHA, ClickFix instruction, or error depending on campaign state and visitor attributes. The lure is a presentation layer. Underneath it, the compromised-site supply, external script, cookie and device checks, command infrastructure, and payload handoff can provide more durable detection opportunities.
Collect the injected code and where it was inserted, external script URLs, parameter structure, cookies, request sequence, landing-page content, delivered artifacts, and endpoint processes. Website remediation must find persistence and the original access path. If only the visible lure domain is blocked, the TDS can rotate the destination while thousands of compromised sources continue feeding it.
Campaign evidence should remain temporal
A central server, certificate, domain, or IP can change. Passive DNS shows that a provider observed a relationship at a time; it does not establish permanent control. WordPress sites can be cleaned and later reinfected by another actor. Payload servers can host several customers or be reassigned.
Build a dated evidence table with first and last observation, collection source, relationship, confidence, and alternatives. Behavioral detections—unexpected external JavaScript on a website, cookie-gated navigation, fake verification pages, clipboard-to-shell execution, and browser-child processes—survive longer than a list of domains. Use indicators as time-bounded accelerators, not as the entire analytic product.
Resources
- Virus Bulletin 2025: TAG-124 — Read the technical paper on TAG-124 modular routing, label overlaps, URL rotation, and delivery logic.
- Red Canary: KongTuke — Use the current threat profile for behavioral analysis and defensive actions.