KongTuke’s stealth foothold now looks brokered

The real shift is that Mistic is now being treated as a handoffable access package, not just a backdoor name. It is tied to Woodgnat/KongTuke and shown deployed with ModeloRAT, which points to durable, low-visibility access that can be sold or reused before ransomware ever starts. Symantec and Carbon Black say the activity has hit insurance, education, IT, and professional services since April 2026. The backdoor runs in memory, can delete itself, and was used alongside a Python RAT, with reporting also tying KongTuke to earlier ClickFix-style intrusions that trick users into running commands under a false security prompt. That changes cleanup from 'remove the malware' to 'assume access may already be established and brokered onward.' Even if no file is left behind, the foothold can still be alive in memory or already passed to another crew.

Part of the PlainSec briefing for 2026-06-25

Sources