APT / THREAT GROUP

ModeloRAT

2
aliases
Last seen:Jul 23, 2026

Intelligence Profile

According to Rapid7, ModeloRAT is a Python-based remote access trojan framework previously tied to the KongTuke group's browser extension campaigns, which in this incident was delivered through Microsoft Teams social engineering using a portable WinPython environment to bypass traditional detections. Its capabilities center on a long-running HTTP C2 beacon that can load DLLs via rundll32, launch additional Python modules, execute PowerShell commands, install MSI packages, handle persistence, and self-update or remove, while supporting supplementary modules for reverse shells, SOCKS proxying, and HTTP tunneling. The Python modules are obfuscated and run through pythonw.exe to avoid visible console windows, with all communication blended into normal-looking web traffic over port 80.

Threat Analysis

ModeloRAT is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.

Intelligence Reports Mentioning ModeloRAT

External References

Quick Facts

TypeAPT / Threat Group
Aliases2

Also Known As

py.modeloratModeloRAT

External Intelligence

Malpedia: py.modelorat

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.