logo

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

ID: 9a20f464-088e-5457-9e2d-fb787653db65

STIX ID: report--9a20f464-088e-5457-9e2d-fb787653db65

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: [email protected] (The Hacker News)

...
...

**Mistic** is a stealthy in-memory backdoor (tracked as MLTBackdoor) used since April 2026 by initial access broker KongTuke to provide long-term, low-visibility access to multiple sectors; it is distributed via ClickFix-style chains (malicious Chrome extension, DNS staging, Teams lures), employs DLL sideloading with trusted Microsoft tooling, can execute code and load BOFs in memory, and has been linked to ModeloRAT and subsequent ransomware activity (e.g., Qilin).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.