A new stealthy backdoor called Mistic (also tracked as MTLBackdoor by Zscaler) has been linked to KongTuke/Woodgnat, an initial access broker active since 2024 that sells corporate network access to ransomware groups including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Mistic is deployed via DLL side-loading using a legitimate Microsoft executable, disguises itself with names resembling Microsoft endpoint security tooling, and runs payloads entirely in memory with no disk writes. Key capabilities include file operations, C2 beacon interval modification, in-memory code execution, and a kill switch for self-deletion. Notably, it supports Beacon Object Files (BOFs) — a technique common in red team tools like Cobalt Strike — allowing capability expansion without leaving disk artifacts. The backdoor has been observed in attacks targeting insurance, education, IT, and professional services sectors since at least April 2025, often deployed alongside ModeloRAT via ClickFix-style social engineering.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Mistic attack chainRelated Articles:
274 Impressions