Stealthy Mistic backdoor linked to ransomware access broker KongTuke
ID: 599f8f1b-9052-5edc-8548-5c2e04ae67d4
STIX ID: report--599f8f1b-9052-5edc-8548-5c2e04ae67d4
Feed Name: Bleeping Computer
Symantec and Zscaler report a stealthy backdoor named Mistic (tracked as MTLBackdoor) used since April by the KongTuke initial access broker to gain long-term, low-visibility access in organizations across insurance, education, IT, and professional services; Mistic is delivered via DLL side‑loading and multi-stage ClickFix/ModeloRAT chains (including social engineering over Microsoft Teams), supports file operations, in-memory execution (including BOFs), and a kill switch, and has been used to facilitate access sold to multiple ransomware groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
