Symantec and Zscaler link new Mistic backdoor to KongTuke ransomware access broker

Researchers say a newly identified backdoor called Mistic is being used to quietly keep access inside company networks in attacks tied to KongTuke, an initial access broker linked to ransomware groups. Symantec says Mistic has been used since April 2026 against organizations in insurance, education, IT, and professional services, including deployment after ModeloRAT in at least one case. The malware is side-loaded through MpExtMs.exe and a malicious version.dll, can run payloads in memory, steal credentials via a fake login prompt, and receive commands from attacker-controlled servers; Zscaler says it also appeared in a multi-stage ClickFix infection chain and can load Beacon Object Files for in-memory post-exploitation.
Why it matters: Organizations in the named sectors may be facing a low-visibility foothold used to prepare ransomware attacks, not just one-off malware infections. Defenders should hunt for KongTuke and ClickFix activity, review Symantec and Zscaler indicators, and watch for suspicious DLL side-loading, fake login prompts, and Microsoft Teams-based social engineering.

Sources

Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs
2026.06.25 96% relevant
This article is a direct follow-on to the same Mistic/KongTuke event, adding that Symantec and Carbon Black saw Mistic in multiple intrusions since April across insurance, education, IT, and professional services, including one case where it appeared alongside KongTuke's ModeloRAT and was side-loaded via MpExtMs.exe and EndpointDlp.dll.
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
info@thehackernews.com (The Hacker News) 2026.06.25 98% relevant
This is the same underlying event: reporting on the newly identified Mistic backdoor and its connection to the KongTuke access-broker ecosystem, including its use in ClickFix and ModeloRAT-linked delivery campaigns.
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
Ionut Arghire 2026.06.24 98% relevant
This is the same underlying event: reporting on the new Mistic RAT/MLTBackdoor used by the KongTuke/Woodgnat initial access broker. It adds detail that the actor has used Mistic since April 2026, is targeting education, insurance, IT, and professional services, and is using Microsoft Teams helpdesk lures plus ClickFix/FileFix/CrashFix-style social engineering to get victims to run malicious PowerShell.
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
Bill Toulas 2026.06.24 100% relevant
This article establishes a distinct threat story by introducing Mistic as a newly reported backdoor and concretely linking it to KongTuke's ransomware-access operations across multiple sectors.
← Back to all stories