www.security.com New Mistic Backdoor Linked to Ransomware Access Broker Activity
Article Content
- •Mistic backdoor linked to ransomware broker KongTuke has been active since April 2026.
- •The malware is delivered via DLL sideloading using legitimate Microsoft Defender executables.
- •Mistic supports stealthy operations, executing payloads in memory without leaving traces on disk.
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to ransomware groups like Qilin and Interlock. Mistic is delivered through DLL sideloading, using a legitimate Microsoft Defender executable (MpExtMs.exe) to load a malicious DLL (EndpointDlp.dll) directly into memory, avoiding detection. This backdoor supports standard functionalities like file manipulation and remote payload execution without leaving traces on disk. The attacks have affected organizations in insurance, education, IT, and professional services. Symantec's Threat Hunter Team has observed Mistic's deployment alongside ModeloRAT, enhancing the stealth and persistence of these operations. The malware's design emphasizes long-term access, with features like a kill switch for self-deletion.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (21)
Following this threat?
Track 8Base, ClickFix and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's Hybrid Warfare Threatens UK with Cyberattacks and Sabotage Russia has escalated threats against the UK following its support for Ukraine, warning of 'consequences' for British involvement. Concurrently, Russian-linked cyberattacks, including a ransomware attack on the pathology lab Synnovis, have severely disrupted NHS services in London, affecting over 800 operations and 700…
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…