Frequency
6
occurrences
First Seen
June 24, 2026
Last Seen
September 3, 2026
Related Threat Clusters
-
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique…
8 articles · Updated September 3, 2026 -
New Mistic Backdoor Linked to Ransomware Access Broker Activity
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
21 articles · Updated June 24, 2026
Recent Intelligence Reports
- Node Js Returns Ransomware — www.security.com · September 3, 2026
- Node.js: Old Technique Makes a Comeback — Security · September 3, 2026
- Technical Analysis Mltbackdoor — www.zscaler.com · June 25, 2026
- Symantec’s Threat Hunter Team observed ModeloRAT — www.security.com · June 24, 2026
- Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
- Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026