Threats · 81 days ago
KongTuke’s stealth foothold now looks brokered The real shift is that Mistic is now being treated as a handoffable access package, not just a backdoor name. It is tied to Woodgnat/KongTuke and shown deployed with ModeloRAT, which points to durable, low-visibility access that can be sold or reused before ransomware ever starts.
Symantec and Carbon Black say the activity has hit insurance, education, IT, and professional services since April 2026. The backdoor runs in memory, can delete itself, and was used alongside a Python RAT, with reporting also tying KongTuke to earlier ClickFix-style intrusions that trick users into running commands under a false security prompt.
That changes cleanup from 'remove the malware' to 'assume access may already be established and brokered onward.' Even if no file is left behind, the foothold can still be alive in memory or already passed to another crew.
Timeline Sources 5 sources covering this story
The Hacker News Jun 25
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
Symantec and Carbon Black link Mistic backdoor attacks to KongTuke, using ClickFix lures and in-memory execution for stealthy access.
Help Net Security Jun 25
Stealthy new backdoor surfaces in attacks on multiple sectors - Help Net Security
A relatively new backdoor called Mistic appears to be linked to Woodgnat and has been used in attacks targeting multiple sectors.
CSO Online Jun 24
Be on the lookout for Mistic, a new backdoor used by ransomware broker
The malware program has been deployed across multiple sectors since April, helping to provide initial access sold to ransomware gangs.
SecurityWeek Jun 24
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
BleepingComputer Jun 24
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors.
Entities Part of the PlainSec briefing for 2026-06-25
Editions Related stories
Threats · 81 days ago
KongTuke’s stealth foothold now looks brokered The real shift is that Mistic is now being treated as a handoffable access package, not just a backdoor name. It is tied to Woodgnat/KongTuke and shown deployed with ModeloRAT, which points to durable, low-visibility access that can be sold or reused before ransomware ever starts.
Symantec and Carbon Black say the activity has hit insurance, education, IT, and professional services since April 2026. The backdoor runs in memory, can delete itself, and was used alongside a Python RAT, with reporting also tying KongTuke to earlier ClickFix-style intrusions that trick users into running commands under a false security prompt.
That changes cleanup from 'remove the malware' to 'assume access may already be established and brokered onward.' Even if no file is left behind, the foothold can still be alive in memory or already passed to another crew.
Timeline Sources 5 sources covering this story
The Hacker News Jun 25
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
Symantec and Carbon Black link Mistic backdoor attacks to KongTuke, using ClickFix lures and in-memory execution for stealthy access.
Help Net Security Jun 25
Stealthy new backdoor surfaces in attacks on multiple sectors - Help Net Security
A relatively new backdoor called Mistic appears to be linked to Woodgnat and has been used in attacks targeting multiple sectors.
CSO Online Jun 24
Be on the lookout for Mistic, a new backdoor used by ransomware broker
The malware program has been deployed across multiple sectors since April, helping to provide initial access sold to ransomware gangs.
SecurityWeek Jun 24
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
BleepingComputer Jun 24
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors.
Entities Part of the PlainSec briefing for 2026-06-25
Editions Related stories