Stealthy new backdoor surfaces in attacks on multiple sectors
ID: 056eae26-40f0-5664-a4db-58b84d27be54
STIX ID: report--056eae26-40f0-5664-a4db-58b84d27be54
Feed Name: Help Net Security
Threat Score
Symantec observed a new backdoor named Mistic (also documented as MLTBackdoor) deployed since April 2026 by the financially motivated initial access broker Woodgnat across insurance, education, IT, and professional services; Mistic is stealthy (in-memory execution and a kill switch), was side‑loaded through legitimate binaries (MpExtMs.exe/EndpointDlp.dll), was used alongside ModeloRAT and living‑off‑the‑land tools, and Symantec published associated IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
