Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection
ID: 072efa27-18c8-59f3-8357-972e45f4000c
STIX ID: report--072efa27-18c8-59f3-8357-972e45f4000c
Feed Name: cybersecurityNews.com
Mistic is a stealthy, in-memory backdoor observed since April 2026 that masquerades as Microsoft endpoint security via DLL sideloading (MpExtMs.exe loading EndpointDlp.dll). Linked by Symantec to the financially motivated Woodgnat group, the tool includes a loader (version.dll), credential-stealing .NET components, file transfer and remote code execution capabilities, and a kill switch; operators sell access to ransomware affiliates. The report provides multiple IoCs (SHA-256 hashes, IPs, domains) and recommends monitoring for DLL sideloading, in-memory execution, and abnormal use of built-in Windows tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
