Emergence of Mistic Backdoor Linked to Ransomware Access Broker KongTuke

Emergence of Mistic Backdoor Linked to Ransomware Access Broker KongTuke

2h ago SecurityBleepingcomputerwww.security.comFeeds.4Sysopswww.zscaler.com 89% similarity 69.5
Share:

Article Content

Browse articles
ThreatCluster

The Mistic backdoor has been identified as a new threat in cybercrime campaigns since April 2026, targeting sectors such as insurance, education, and IT. It is linked to the initial access broker KongTuke, which sells network access to ransomware groups like Qilin and Black Basta. Mistic is often deployed alongside the ModeloRAT and is delivered through social engineering tactics or multi-stage infection chains, including the use of legitimate executables like MpExtMs.exe for DLL sideloading. The backdoor allows attackers to execute remote payloads in memory, enhancing stealth and persistence. Researchers at Symantec have observed its deployment in various organizations, emphasizing its stealthy nature and long-term access capabilities. The malware's design includes features like a kill switch and the ability to load Beacon Object Files (BOFs), which helps it evade detection. Current investigations continue to assess the full scope of its impact.

Key Points: • Mistic backdoor linked to KongTuke has been active since April 2026. • Targets include insurance, education, and IT sectors, using social engineering for delivery. • Features include memory execution and a kill switch for stealthy long-term access.

ThreatCluster AI

Timeline

2026-04-01
Mistic backdoor first observed
Mistic was identified in attacks targeting various sectors, marking its emergence in cybercrime.
Security
2026-05-01
Zscaler documents MLTBackdoor
Zscaler released a technical analysis of MLTBackdoor, detailing its capabilities and infection methods.
Zscaler
2026-06-01
Mistic linked to ModeloRAT
Symantec reported that Mistic is often deployed alongside ModeloRAT, enhancing its stealth.
Bleepingcomputer
2026-06-24
Current threat status
Mistic continues to be a significant threat, with ongoing investigations into its impact and methods.
Feeds.4Sysops

Community

Browse all →