WinPython - Tool

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
January 21, 2026
Last Seen
June 25, 2026

Related Threat Clusters

  • New Mistic Backdoor Linked to Ransomware Access Broker Activity

    A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…

    21 articles · Updated June 24, 2026
  • CrashFix Campaign Delivers ModeloRAT via Malicious Chrome Extension

    A malicious campaign named CrashFix has been identified, utilizing a fake ad-blocking browser extension called NexShield to crash users' browsers. This tactic is employed to facilitate ClickFix attacks, delivering a new…

    3 articles · Updated January 20, 2026

Recent Intelligence Reports

  • Stealthy Mistic Backdoor Targets Enterprise Networks via KongTuke Ransomware Access Broker — Rescana · June 25, 2026
  • Symantec’s Threat Hunter Team observed ModeloRAT — www.security.com · June 24, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
  • ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker — Gbhackers · June 24, 2026
  • Stealthy Mistic backdoor linked to ransomware access broker KongTuke — Bleepingcomputer · June 24, 2026
  • Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
  • Malicious ad blocker extension uses 'CrashFix' to spread new Python RAT — Scmagazine · January 21, 2026

CVSS v3.1 Breakdown