Skip to content

Malware

AkdoorTea

AkdoorTea is a simple TCP RAT. In August 2025, it was contained in a trojanized Nvidia CUDA toolkit package, delivered probably via the ClickFix technique.

AkdoorTea is a Windows malware family operated by WageMole.

Background

AkdoorTea is a straightforward TCP-based RAT. In August 2025 it appeared inside a trojanized Nvidia CUDA toolkit package, most likely distributed using the ClickFix technique. Because the same package also bundled an obfuscated BeaverTail payload, the malware is linked to the Contagious Interview campaigns. To obscure its network traffic, AkdoorTea applies Base64 encoding together with a single-byte XOR key. The RAT recognizes five commands, including one that returns its internal version number, "01.01". Its name reflects its resemblance to an earlier TCP RAT called "Akdoor", which was deployed via ActiveX exploits against South Korean victims in April 2018.


Source: Malpedia (Fraunhofer FKIE).