Back Gbhackers Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access.
The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterprise environments and minimize forensic traces.
Mistic is introduced via a DLL sideloading chain that abuses a legitimate executable named MpExtMs.exe. A malicious loader hooks Windows API functions responsible for library loading and path resolution and forces the process to load a trojanized library called EndpointDlp.dll.
The chosen DLL name mimics Microsoft endpoint components, increasing the chance that the malicious module will appear benign during cursory inspection and that it will run inside trusted host processes.
Once loaded, Mistic supports classic backdoor functions file upload and download, file and directory management, command polling-interval changes, and remote code execution but its standout capability is executing operator-supplied payloads directly in memory, avoiding writing those payloads to disk.
In-memory execution plus DLL sideloading reduces the visibility of Mistic to signature-based scanners and disk-centric forensics.
The backdoor also contains a built-in kill switch allowing operators to terminate and delete components, further erasing evidence after operations or when access is sold or exhausted.
Researchers from Symantec and other vendors documented Mistic alongside ModeloRAT in at least one compromise, creating a plausible operational link to the initial access broker Woodgnat (aka KongTuke), which has a history of selling footholds to ransomware affiliates.
During observed intrusions, defenders found Mistic deployed alongside a .NET credential-stealing component that displayed a fake login screen to harvest credentials, and operators used legitimate administrative tools PowerShell, WMIC, curl, certutil, net.exe, reg.exe alongside custom implants.
This toolset suggests an emphasis on stealthy credential harvesting and persistence rather than immediate disruptive activity.
Operational context strengthens concerns a connection to Woodgnat. Public reporting links Woodgnat to campaigns that abuse compromised WordPress infrastructure ClickFix, FileFix and CrashFix social-engineering chains to convince victims to run attacker-supplied PowerShell commands.
Those chains have previously delivered ModeloRAT and other tooling used to establish and sell access. Symantec and Carbon Black reported Mistic activity and noted deployments in insurance, education, IT, and professional services organizations, consistent with Woodgnat’s opportunistic, access-broker model.
The observed co-deployment of ModeloRAT with Mistic in at least one incident provides circumstantial but meaningful overlap with known Woodgnat operations.
For defenders, Mistic underscores the need for behavioral and memory-focused detection over reliance on signatures alone.
Detection strategies should include monitoring for anomalous DLL loads into trusted processes, API-hooking behaviors that alter library resolution, unexpected in-memory code injection, and suspicious use of built-in administrative utilities immediately following web-exploitation or social-engineering activity.
Threat hunting queries that correlate unusual EndpointDlp.dll loads, network command-and-control patterns, and post-exploitation credential-harvesting UI artifacts will help surface hidden compromises.
Attribution remains tentative, but the convergence of delivery methods, tooling, and targeted sectors merits heightened monitoring and rapid sharing of telemetry.
Analysts recommend isolating suspicious hosts, collecting volatile memory for analysis, and searching for related artifacts such as modified MpExtMs.exe execution chains and signs of ModeloRAT or credential-stealer activity.
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.
A newly disclosed high-severity vulnerability in Splunk Secure Gateway (SSG) allows low-privileged authenticated users to…
Analysis of a .NET backdoor tracked as STOCKSTAY exposes a mature, modular espionage implant actively…
A critical security vulnerability, identified as CVE-2026-50160, has been discovered in the self-hosted Hoppscotch backend.…
The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub,…
Threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution (RCE) vulnerability in…
A newly documented injection technique abuses the kernel-to-user callback dispatch path used by the Windows…
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
