AUTO-UPDATED

New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

Cybersecurity researchers have identified a stealthy new backdoor called Mistic, deployed by the threat actor KongTuke to facilitate financially motivated attacks across multiple industries since April 2026.

Key Points

  • The Mistic backdoor, also known as MLTBackdoor, operates entirely in memory to avoid detection and includes a self-deletion kill switch.
  • Threat actor KongTuke, also tracked as Woodgnat and TAG-124, uses the backdoor alongside the Python-based remote access trojan ModeloRAT.
  • Attackers utilize DLL side-loading via legitimate Microsoft security tools to maintain persistence and evade traditional endpoint security monitoring.
  • Delivery vectors include ClickFix campaigns, malicious browser extensions, and fraudulent Microsoft Teams messages sent from fake IT support accounts.
  • The group operates a traffic distribution system on compromised WordPress sites to target organizations in the insurance, education, IT, and professional services sectors.

Why it Matters

This campaign highlights a growing trend of initial access brokers developing sophisticated, custom malware to sell entry points to ransomware affiliates. By prioritizing stealth and memory-resident execution, these actors pose a significant challenge to organizations attempting to detect and remediate unauthorized network access.
Internet Published by info@thehackernews.com (The Hacker News)
Read original