logo

Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection

ID: 072efa27-18c8-59f3-8357-972e45f4000c

STIX ID: report--072efa27-18c8-59f3-8357-972e45f4000c

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-24

Date Updated: 2026-06-25

Author: Tushar Subhra Dutta

...
...

Mistic is a stealthy, in-memory backdoor observed since April 2026 that masquerades as Microsoft endpoint security via DLL sideloading (MpExtMs.exe loading EndpointDlp.dll). Linked by Symantec to the financially motivated Woodgnat group, the tool includes a loader (version.dll), credential-stealing .NET components, file transfer and remote code execution capabilities, and a kill switch; operators sell access to ransomware affiliates. The report provides multiple IoCs (SHA-256 hashes, IPs, domains) and recommends monitoring for DLL sideloading, in-memory execution, and abnormal use of built-in Windows tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.