Skip to content
New Mistic Backdoor Linked to Ransomware Access Broker Activity

New Mistic Backdoor Linked to Ransomware Access Broker Activity

First seen 24 Jun 2026, 11:41 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 25, 2026 at 11:39 UTC
  • Mistic backdoor linked to ransomware broker KongTuke has been active since April 2026.
  • The malware is delivered via DLL sideloading using legitimate Microsoft Defender executables.
  • Mistic supports stealthy operations, executing payloads in memory without leaving traces on disk.

A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to ransomware groups like Qilin and Interlock. Mistic is delivered through DLL sideloading, using a legitimate Microsoft Defender executable (MpExtMs.exe) to load a malicious DLL (EndpointDlp.dll) directly into memory, avoiding detection. This backdoor supports standard functionalities like file manipulation and remote payload execution without leaving traces on disk. The attacks have affected organizations in insurance, education, IT, and professional services. Symantec's Threat Hunter Team has observed Mistic's deployment alongside ModeloRAT, enhancing the stealth and persistence of these operations. The malware's design emphasizes long-term access, with features like a kill switch for self-deletion.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-04-01
Mistic backdoor first observed
Mistic was identified in cyberattacks targeting various sectors, linked to the initial access broker KongTuke.
BleepingComputer
2026-06-09
CVE-2026-45502 published
A vulnerability was disclosed that may be exploited in conjunction with Mistic backdoor operations.
Gbhackers
2026-06-24
Zscaler reports on MLTBackdoor
Zscaler identified MLTBackdoor, tracking it as Mistic, detailing its infection chain and capabilities.
Zscaler

More articles in this cluster (21)

Following this threat?

Track 8Base, ClickFix and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed