ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker
ID: 02e92735-c29f-5d76-9654-dc85be600a43
STIX ID: report--02e92735-c29f-5d76-9654-dc85be600a43
Feed Name: GBHackers
Threat Score
The report details activity by an access broker (Woodgnat) using ModeloRAT and a newly observed stealth backdoor, Backdoor.Mistic, to establish long-term, low-visibility enterprise access for resale to ransomware affiliates; it outlines the intrusion chain (credential theft, living-off-the-land, signed carriers, in-memory execution), defensive tradecraft observed (DLL sideloading, kill switch, RC4 C2), affected sectors, and provides multiple SHA256 IOCs and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
