Cybersecurity researchers have identified a stealthy new backdoor called Mistic, deployed by the threat actor KongTuke to facilitate financially motivated attacks across multiple industries since April 2026.
Key Points
- The Mistic backdoor, also known as MLTBackdoor, operates entirely in memory to avoid detection and includes a self-deletion kill switch.
- Threat actor KongTuke, also tracked as Woodgnat and TAG-124, uses the backdoor alongside the Python-based remote access trojan ModeloRAT.
- Attackers utilize DLL side-loading via legitimate Microsoft security tools to maintain persistence and evade traditional endpoint security monitoring.
- Delivery vectors include ClickFix campaigns, malicious browser extensions, and fraudulent Microsoft Teams messages sent from fake IT support accounts.
- The group operates a traffic distribution system on compromised WordPress sites to target organizations in the insurance, education, IT, and professional services sectors.