Since April 2026, the threat actor Woodgnat, also tracked as KongTuke, has been deploying a remote access trojan called Backdoor.Mistic against organizations globally. The Broadcom Symantec and Carbon Black threat hunter team reported that this initial access broker, which has links to multiple ransomware families, has used the new RAT in recent attacks.

Woodgnat has been observed delivering the backdoor as a DLL, executing it via sideloading. Symantec researchers stated that Mistic has been used in intrusions since April. In attacks investigated by Symantec, the infection process began with the launch of the legitimate executable MpExtMs.exe to side-load a malicious DLL named version.dll. The version.dll file acts as the loader for Mistic, which is identified as EndpointDlp.dll.

The threat actor has been using helpdesk and IT-support lures delivered through Microsoft Teams to persuade victims to execute malicious code since April 2026. The initial access broker uses social engineering tactics to trick users into running attacker-supplied commands, including ClickFix, FileFix, and CrashFix techniques. The Broadcom threat hunter team noted, "In each case the victim is ultimately tricked into running an attacker-supplied PowerShell command."

Mistic is also tracked as MLTBackdoor and is described by Symantec as a newly developed backdoor designed for long-term persistence within compromised networks. Once loaded, Mistic communicates with its command-and-control infrastructure, receiving various commands from the operator. Its capabilities include file download and upload, file manipulation, folder creation, and code execution. Attackers can modify the frequency at which Mistic checks for new commands and instruct it to terminate itself.

Broadcom researchers indicated that the targeting appears opportunistic. They stated, "The targeting appears to be opportunistic, with the attackers casting a wide net and then assessing which organizations they could sell access to rather than focusing on a single sector." They further explained, "While the initial compromise may be opportunistic, the attackers profile the machines for potential interest to determine their value and if they can sell access to them."

In a recent attack, a credentials stealer was deployed alongside Mistic. The filename chosen for Mistic resembles Microsoft endpoint security tooling. KongTuke has been active since at least May 2024 and has ties to ransomware groups such as Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Targeted industries include education, insurance, IT, and professional services.