BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Mistic Backdoor Deployed in Ransomware-Linked Attacks

Stealthy Mistic backdoor deployed via ClickFix campaigns for long-term access and ransomware

  • A new backdoor named Mistic has been deployed in financially motivated attacks across insurance, education, IT, and professional services since April 2026.
  • The backdoor is linked to the initial access broker KongTuke and is distributed via ClickFix campaigns, often alongside the ModeloRAT remote access trojan.
  • Mistic is designed for stealth, executing payloads directly in memory with a self-deletion feature to avoid detection and maintain long-term access.
  • Targeting appears opportunistic, with attackers potentially assessing which compromised organizations to sell access to, and the campaign has been linked to subsequent Qilin ransomware deployment.

Cybersecurity researchers have uncovered a stealthy new backdoor called Mistic being used in suspected financially motivated attacks against organizations in insurance, education, IT, and professional services since April 2026. The malware, also tracked as MLTBackdoor, is linked to the initial access broker KongTuke and was dropped alongside the Python-based ModeloRAT, according to a report from Broadcom’s cybersecurity teams shared with The Hacker News.

- Advertisement -

The attackers primarily used malicious ClickFix campaigns, which trick users into running commands after a browser crash, to deliver their payload. Zscaler ThreatLabz highlighted this delivery method earlier in June 2026, attributing it to a ransomware-related threat actor.

Consequently, the backdoor employs advanced techniques like DLL side-loading through a trusted Microsoft security tool to avoid raising alarms. It runs entirely in memory, granting it capabilities to upload/download files, execute remote code, and even load Beacon Object Files to expand its functions.

“The backdoor runs payloads in memory with no file written to disk and includes a kill switch that lets it delete itself, which are features consistent with an operator seeking long-term, low-visibility access,” the researchers noted. The targeting appears opportunistic, with the attackers casting a wide net to later sell access, Symantec and Carbon Black said, adding that ModeloRAT has been seen in attacks that deployed Qilin ransomware.

Meanwhile, the KongTuke group has evolved its tactics, recently using a fake IT Support account to send malicious Microsoft Teams messages. “The use of custom tools in ransomware attacks is becoming a more common phenomenon,” Broadcom stated, suggesting Mistic continues this trend, likely developed by access brokers for ransomware affiliates.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OCC fines AmEx $350M over $13B money laundering

The OCC found American Express National Bank processed approximately $13 billion in suspected trade-based...

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading