Relevance: primary · Type: action
Confidence100%
Broadcom’s Symantec and Carbon Black threat hunter team reports that an initial access broker linked to multiple ransomware families has been using a new remote access trojan in recent attacks.
Relevance: primary · Type: background
Confidence100%
The threat actor is tracked as Woodgnat and KongTuke.
Relevance: primary · Type: background
Confidence100%
Woodgnat and KongTuke have been active since at least May 2024.
Relevance: primary · Type: background
Confidence100%
Woodgnat and KongTuke are known to have ties to ransomware groups Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
Relevance: primary · Type: event
Confidence100%
Starting in April 2026, Woodgnat has been deploying the Backdoor.Mistic RAT against networks of organizations across multiple industries.
Relevance: supporting · Type: background
Confidence100%
Targeted industries include education, insurance, IT, and professional services.
Relevance: supporting · Type: background
Confidence100%
Previously, the threat actor was observed deploying ModeloRAT in attacks targeting other entities.
Broadcom researchers, researchers
Relevance: supporting · Type: quote
Confidence100%
"The targeting appears to be opportunistic, with the attackers casting a wide net and then assessing which organizations they could sell access to rather than focusing on a single sector."
Relevance: supporting · Type: background
Confidence100%
Mistic is also tracked as MLTBackdoor.
Relevance: supporting · Type: background
Confidence100%
Mistic provides attackers with capabilities including file download and upload, file manipulation, folder creation, and code execution.
Relevance: supporting · Type: background
Confidence100%
Attackers can modify the frequency at which Mistic checks for new commands.
Relevance: supporting · Type: background
Confidence100%
Attackers can instruct Mistic to terminate itself.
Relevance: primary · Type: action
Confidence100%
Woodgnat has been deploying the backdoor as a DLL, executing it via sideloading.
Relevance: supporting · Type: event
Confidence100%
In a recent attack, the threat actor deployed a credential stealer alongside Mistic.
Relevance: supporting · Type: background
Confidence100%
Additional tools observed in the intrusion include Curl, Reg.exe, Net (net.exe), PowerShell, Certutil, and WMIC.
Relevance: supporting · Type: background
Confidence100%
These tools are used for data exfiltration, registry manipulation, network resource management, command execution, reconnaissance, lateral movement, file download, and browser certificate installation.
Relevance: supporting · Type: background
Confidence100%
The initial access broker is known for distributing malware via compromised WordPress sites.
Relevance: supporting · Type: background
Confidence100%
The initial access broker relies on social engineering to entice users into executing attacker-supplied commands, including ClickFix, FileFix, and CrashFix techniques.
Broadcom threat hunter team, threat hunter team
Relevance: supporting · Type: quote
Confidence100%
"In each case the victim is ultimately tricked into running an attacker-supplied PowerShell command."
Broadcom threat hunter team, threat hunter team
Relevance: supporting · Type: quote
Confidence100%
"While the initial compromise may be opportunistic, the attackers profile the machines for potential interest to determine their value and if they can sell access to them."
Relevance: primary · Type: action
Confidence100%
Since April 2026, the threat actor has been using helpdesk and IT-support lures delivered via Microsoft Teams to convince victims into executing malicious code.
Relevance: primary · Type: action
Confidence100%
Symantec researchers say that Mistic has been used in intrusions since April.
Relevance: supporting · Type: background
Confidence100%
Symantec believes Mistic is a newly developed, stealthy backdoor designed for long-term persistence in compromised networks.
Relevance: primary · Type: event
Confidence100%
In attacks investigated by Symantec, the infection started with the launch of the legitimate executable MpExtMs.exe to side-load a malicious DLL named version.dll.
Relevance: supporting · Type: background
Confidence100%
The version.dll file acts as the loader of Mistic (EndpointDlp.dll).
Relevance: supporting · Type: background
Confidence100%
The filename chosen for Mistic resembles Microsoft endpoint security tooling.
Relevance: supporting · Type: event
Confidence100%
A separate .NET DLL is loaded which displays a fake login screen to the victim to steal account credentials.
Relevance: supporting · Type: background
Confidence100%
Once loaded, Mistic communicates with its command-and-control infrastructure and can receive commands from the operator.
Relevance: supporting · Type: background
Confidence100%
Symantec lists Mistic capabilities as upload/download, move, rename, delete files, and create folders.
Relevance: supporting · Type: background
Confidence100%
Symantec lists Mistic capabilities as modifying how frequently it checks for commands from the command-and-control server.
Relevance: supporting · Type: background
Confidence100%
Symantec lists Mistic capabilities as executing code received from the C2 directly in memory.
Relevance: supporting · Type: background
Confidence100%
Symantec lists Mistic capabilities as terminating itself and deleting files from the host.
Symantec researchers, researchers
Relevance: supporting · Type: quote
Confidence100%
"The backdoor runs payloads in memory with no file written to disk and includes a kill switch that lets it delete itself, which are features consistent with an operator seeking long-term, low-visibility access."
Relevance: primary · Type: event
Confidence100%
Zscaler notes that Mistic, tracked as MTLBackdoor, was delivered as a payload in a multi-stage ClickFix infection chain in May.
Zscaler researchers, researchers
Relevance: supporting · Type: quote
Confidence100%
Zscaler researchers say that "one of the most powerful features [in MTLBackdoor] is the ability to load Beacon Object Files (BOFs) to expand its capabilities."
Relevance: supporting · Type: background
Confidence100%
BOFs are small programs in C that can execute directly in the memory of a command-and-control process.
Relevance: supporting · Type: background
Confidence100%
BOFs leave no footprint on the disk and evade detection of security agents.
Relevance: supporting · Type: background
Confidence100%
KongTuke is known to use multiple other tools such as WinPython and Node.js runtimes to execute malicious code.
Relevance: supporting · Type: background
Confidence100%
KongTuke is known to use finger.exe to retrieve obfuscated payloads.
Relevance: supporting · Type: background
Confidence100%
KongTuke is known to use the fake NexShield browser extension.
Relevance: supporting · Type: background
Confidence100%
KongTuke is known to use the encrypted GateKeeper .NET payload.
Relevance: supporting · Type: background
Confidence100%
KongTuke is known to use MintsLoader and D3F@ck Loader malware loaders to deliver additional payloads.
Relevance: supporting · Type: background
Confidence100%
Both Zscaler and Symantec reports provide indicators of compromise for the Mistic/MTLBackdoor malware.
forum Comments (0)
No comments yet. Be the first to comment.