Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker
ID: 0328383d-84c2-52c2-818c-10bd03ca0485
STIX ID: report--0328383d-84c2-52c2-818c-10bd03ca0485
Feed Name: security.com
Symantec researchers describe Backdoor.Mistic, a stealthy Windows backdoor first observed in April 2026 that is sideloaded via a legitimate executable and runs payloads entirely in memory with a built-in kill switch; the report links Mistic to the financially motivated initial-access group Woodgnat (aka KongTuke), notes ties to ModeloRAT and observed ransomware delivery (Qilin), details attacker TTPs (paste-and-run social engineering, sideloading, in-memory execution), and provides extensive file and network IOCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
