logo

Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker

ID: 0328383d-84c2-52c2-818c-10bd03ca0485

STIX ID: report--0328383d-84c2-52c2-818c-10bd03ca0485

Feed Name: security.com

Threat Score
78/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Threat Hunter Team

...
...

Symantec researchers describe Backdoor.Mistic, a stealthy Windows backdoor first observed in April 2026 that is sideloaded via a legitimate executable and runs payloads entirely in memory with a built-in kill switch; the report links Mistic to the financially motivated initial-access group Woodgnat (aka KongTuke), notes ties to ModeloRAT and observed ransomware delivery (Qilin), details attacker TTPs (paste-and-run social engineering, sideloading, in-memory execution), and provides extensive file and network IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.