FileFix Series — Most Significant TTP 2026: Compromised Website Web-Inject Cluster Beacon (KongTuke/LandUpdate808 Pattern)

This rule detects a behavioral chain characteristic of the KongTuke/LandUpdate808 threat actor group. It identifies the correlation between a browser initiating a network connection to a domain with a low-reputation top-level domain (TLD) and that same browser process launching 'explorer.exe' within a 60-second window. This behavior is associated with social engineering lures (fake CAPTCHA) that encourage users to execute clipboard commands, which trigger file-picker dialogs via explorer.exe to facilitate follow-on malicious activity.