Woodgnat Uses ClickFix, FileFix, and CrashFix Lures to Deliver Remote Access Malware

A newly discovered backdoor dubbed Mistic has been identified in multiple cyberattacks since April 2026. Security researchers believe this stealthy malware is linked to Woodgnat, a publicly known financially motivated initial access broker (IAB) also known as KongTuke.

Rather than deploying final ransomware payloads, Woodgnat specializes in establishing highly durable remote access within enterprise networks.

The group then sells this deep network foothold to ransomware affiliates, including those distributing Qilin, Interlock, Rhysida, and Black Basta.

Mistic, which researchers from Zscaler initially tracked as MLTBackdoor, is frequently used alongside Woodgnat’s signature ModeloRAT remote access trojan.

Targeting remains largely opportunistic, hitting sectors such as insurance, education, and IT services as attackers cast a wide net before assessing the financial value of their compromised victims.

Woodgnat Fix Lure Malware

Woodgnat heavily relies on compromised WordPress sites to host its malicious traffic distribution system.

By exploiting vulnerable plugins or using stolen credentials, the group injects malicious JavaScript to profile site visitors and serve highly effective social-engineering lures.

These deceptive tactics trick victims into executing PowerShell commands supplied by attackers. Over the past year, the group has evolved its methods through three distinct phases.

More recently, Woodgnat has expanded its reach by utilizing external Microsoft Teams chats. Attackers pose as IT support desk personnel, walking targeted users through a dangerous “paste-and-run” sequence.

By rotating through multiple Microsoft 365 tenants, operators easily evade reactive blocking measures and achieve persistent network access within minutes of a victim pasting a single PowerShell command.

Backdoor. Mistic is designed specifically for stealth and long-term persistence. The malware executes payloads directly in memory and includes a built-in kill switch that terminates and deletes itself when necessary.

Mistic is typically launched via DLL sideloading. Attackers abuse a legitimate file, MpExtMs.exe, to sideload a malicious payload, EndpointDlp.dll.

During this infection chain, a .NET credential stealer is also loaded to display a fake login screen and harvest user credentials.

Once initial access is achieved, Woodgnat deploys a robust toolkit. The group frequently utilizes ModeloRAT, which is delivered within a portable WinPython package and runs via a signed Python interpreter.

To maintain persistence, attackers create registry Run-key entries disguised as legitimate remote-access software such as AnyDesk, Splashtop, or Comms.

Woodgnat prioritizes operational resilience by using a pool of command-and-control (C2) servers with sequential failover.

By heavily obfuscating payloads for non-domain-joined victims and reserving the full ModeloRAT toolkit for high-value enterprise targets, the group ensures its access remains undetected.

The increasing use of custom, memory-resident tools by IABs signals a shift away from exclusively using living-off-the-land techniques, making advanced detection capabilities essential for modern security teams.

Indicators of Compromise

File HashFile NameDescription / Malware Association
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984endpointdlp.dllBackdoor.Mistic
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcf.dllFake lock screen (Credential stealer)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories