Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions


Inside Mistic, the New Stealth Backdoor in Ransomware Intrusions

Pierluigi Paganini
June 25, 2026

Mistic is a stealthy backdoor used by KongTuke-linked actors to keep long-term access in ransomware-targeted networks.

Mistic is the kind of backdoor that tells you the operator wants time, not noise. Symantec security researchers say it has shown up in financially motivated attacks against insurance, education, IT, and professional services firms, and they link it to KongTuke, also known as Woodgnat, an access broker active since at least 2024. That group has a clear business model: break in, hold the door open, and sell that access to ransomware crews like Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

The infection path looks built for camouflage. In the cases Symantec analyzed, the attack started when the legitimate MpExtMs.exe process loaded a malicious DLL named version.dll, which then dropped the Mistic loader, EndpointDlp.dll. The name looks close enough to Microsoft security tooling to be useful, and that’s probably the point. A separate .NET DLL also showed a fake login screen to steal credentials, because apparently criminals still enjoy borrowing your own trust against you.

“Mistic was side-loaded through MpExtMs.exe, a legitimate file, and loaded from a DLL named EndpointDlp.dll, a name associated with Microsoft endpoint-security tooling. This would help the backdoor blend in with trusted software.” reads the report published by Symantec. “The backdoor runs payloads in memory with no file written to disk and includes a kill switch that lets it delete itself, which are features consistent with an operator seeking long-term, low-visibility access.”

Symantec says Mistic has been used since April, and in at least one case it arrived right after ModeloRAT, another KongTuke-linked backdoor that has spread through Microsoft Teams social engineering. That sort of sequencing is not subtle, but it works often enough that people keep doing it.

Once loaded, Mistic connects to its command-and-control server and waits for instructions. It can upload, download, move, rename, delete files, create folders, change how often it checks in, run code directly in memory, and remove itself from the host. That’s a decent toolbox for a backdoor that’s trying not to look like one.

Zscaler first analyzed the backdoor tracks the same malware family as MTLBackdoor and says it was delivered in a multi-stage ClickFix chain in May.

“A relatively new backdoor that we have called Backdoor.Mistic has been deployed in multiple attacks since April 2026. The backdoor was first documented by Zscaler (which tracks it as MLTBackdoor) earlier this month.” continues the report. “Mistic may be linked to the financially motivated initial access broker (IAB) tracked publicly as KongTuke (which we track as Woodgnat) and it was used in one intrusion that also involved the group’s ModeloRAT remote access trojan.”

Mistic can upload, download, move, delete files, create folders, adjust command-check intervals, and even remove itself through a built-in kill switch. In a recent attack, attackers used DLL sideloading with a legitimate Microsoft executable to load the malware and a credential-stealing component that displayed a fake login screen. The campaign also leveraged common tools such as PowerShell, Curl, Certutil, WMIC, Net.exe and Reg.exe for reconnaissance, persistence, credential theft and lateral movement. Its in-memory execution and self-deletion capabilities make it particularly effective for long-term covert access.

“The fact that Mistic executes in memory and also has a kill switch built in means that it is very stealthy, potentially allowing for long-term, stealthy access for attackers.” continues the report.

KongTuke has also been seen using a wider kit, including WinPython, Node.js, finger.exe, a fake NexShield browser extension, the encrypted GateKeeper .NET payload, and loaders like MintsLoader and D3F@ck Loader. That mix matters because it shows an operator who values flexibility and wants to swap delivery methods fast. In other words, they’re not married to one trick, which is usually a bad sign for the people on the receiving end.

The growing use of custom malware in ransomware operations marks a shift from traditional reliance on legitimate system tools. Backdoor.Mistic appears to fit this trend and is likely developed by access brokers linked to ransomware affiliates rather than a ransomware gang itself. Its stealth features, along with Woodgnat’s suspected role in developing ModeloRAT, highlight a highly skilled group that could expand both its toolset and criminal partnerships.

“The stealth of the backdoor is also notable, as is the fact that Woodgnat is also possibly behind the development of ModeloRAT, indicating a group that is quite highly skilled at the development of stealthy remote access tools.” concludes the report. “This indicates it is a group that should be actively tracked as it could continue to develop custom tools, as well as widen the pool of ransomware actors it works with.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Growing a small business is exhilarating, but the reality of managing its finances can be exhausting. From juggling invoices and tracking expenses to facing year-end taxes, the financial burden often pulls entrepreneurs away from the work they love—and the work that drives growth.

We partnered with BetaKit to showcase the unvarnished stories of two Canadian CEOs who turned their financial operations from a source of stress into a strategic advantage: Emrah Eren of Duco Media and Sean Hoff of Moniker. They share how moving to cloud accounting not only solved their immediate problems but empowered them with the confidence and data to scale their companies.

Hear Their Stories

Emrah Eren, CEO of Duco Media: Conquering the Fear of Year-End

See how Ottawa-based digital marketing agency Duco Media transformed its financial clarity and achieved impressive growth with Xero.

Sean Hoff, CEO of Moniker: Gaining Real-Time Visibility in a Global Business

Discover how Toronto-based corporate retreat company Moniker found the solution to managing complex multi-currency transactions and business growth.

The Chaos of Growth: When Excel Sheets Fail the Entrepreneur

For many small business owners, financial management is a source of anxiety, not confidence. Both Emrah Eren and Sean Hoff faced a common experience: their makeshift financial systems simply couldn’t keep pace with their growing businesses.

For Duco Media, the breaking point wasn’t daily bookkeeping, but a high-stakes funding application during the pandemic. Emrah recalls the painful process of trying to compile the necessary financial statements, which took “hours and hours and hours to produce…”. The sheer difficulty forced him to ask his accountant for a better way.

Moniker’s challenges were amplified by its international scope and rapid expansion—going from 6 or 7 projects to over 20 in a single year. The complex logistics led to a catastrophic lack of visibility. Sean described the feeling of being an entrepreneur without a clear financial view: “You feel like an air traffic controller trying to stay on top of all of these flights that are coming in and out, but half your screens are dark.”

Strategic Relief: Finding the Right Tool for the Job

The key for both CEOs was finding a tool that addressed their specific anxieties and operational complexities.

For Sean Hoff, running a corporate retreat company meant constantly dealing with multi-currency transactions. This complexity demanded a specialized solution, leading Moniker to choose Xero for its core flexibility. Sean highlighted this as a core business enabler: “It was one of the few accounting platforms that allowed multi-currency. We might be getting paid in Euro but taking a group to Mexico, so we’re paying out in Pesos.”.

For Emrah Eren, the impact was deeply personal and immediately psychological. Beyond just the mechanics of bookkeeping, Xero removed the constant worry. He noted a profound relief that many business owners can relate to: “Xero has removed not only the burden of financial management, but I’d also say the fear of a year-end.”

The Outcome: Confidence and Measurable Momentum

Shifting from reacting to financial problems to proactively planning allowed both businesses to accelerate their growth with confidence.

Sean Hoff emphasizes that visibility transforms decision-making, particularly around cash flow. Reliable data now allows Moniker to forecast accurately and set realistic expectations. 

Duco Media saw measurable momentum: their efficiency skyrocketed, with complex, year-over-year financial reports now taking “within a few seconds.” Emrah links this new operational speed directly to their success, resulting in 120% growth in revenue in the first year and a 40% increase in timely payment collection.

For these CEOs, the right financial software wasn’t just about accounting—it was about reclaiming control, easing anxiety, and setting the stage for aggressive, reliable business scaling.

Was this article helpful?

YesNo



Source link