A newly discovered backdoor dubbed Mistic has been identified in multiple cyberattacks since April 2026. Security researchers believe this stealthy malware is linked to Woodgnat, a publicly known financially motivated initial access broker (IAB) also known as KongTuke.
Rather than deploying final ransomware payloads, Woodgnat specializes in establishing highly durable remote access within enterprise networks.
The group then sells this deep network foothold to ransomware affiliates, including those distributing Qilin, Interlock, Rhysida, and Black Basta.
Mistic, which researchers from Zscaler initially tracked as MLTBackdoor, is frequently used alongside Woodgnat’s signature ModeloRAT remote access trojan.
Targeting remains largely opportunistic, hitting sectors such as insurance, education, and IT services as attackers cast a wide net before assessing the financial value of their compromised victims.
Woodgnat Fix Lure Malware
Woodgnat heavily relies on compromised WordPress sites to host its malicious traffic distribution system.
By exploiting vulnerable plugins or using stolen credentials, the group injects malicious JavaScript to profile site visitors and serve highly effective social-engineering lures.
These deceptive tactics trick victims into executing PowerShell commands supplied by attackers. Over the past year, the group has evolved its methods through three distinct phases.
More recently, Woodgnat has expanded its reach by utilizing external Microsoft Teams chats. Attackers pose as IT support desk personnel, walking targeted users through a dangerous “paste-and-run” sequence.
By rotating through multiple Microsoft 365 tenants, operators easily evade reactive blocking measures and achieve persistent network access within minutes of a victim pasting a single PowerShell command.
Backdoor. Mistic is designed specifically for stealth and long-term persistence. The malware executes payloads directly in memory and includes a built-in kill switch that terminates and deletes itself when necessary.
Mistic is typically launched via DLL sideloading. Attackers abuse a legitimate file, MpExtMs.exe, to sideload a malicious payload, EndpointDlp.dll.
During this infection chain, a .NET credential stealer is also loaded to display a fake login screen and harvest user credentials.
Once initial access is achieved, Woodgnat deploys a robust toolkit. The group frequently utilizes ModeloRAT, which is delivered within a portable WinPython package and runs via a signed Python interpreter.
To maintain persistence, attackers create registry Run-key entries disguised as legitimate remote-access software such as AnyDesk, Splashtop, or Comms.
Woodgnat prioritizes operational resilience by using a pool of command-and-control (C2) servers with sequential failover.
By heavily obfuscating payloads for non-domain-joined victims and reserving the full ModeloRAT toolkit for high-value enterprise targets, the group ensures its access remains undetected.
The increasing use of custom, memory-resident tools by IABs signals a shift away from exclusively using living-off-the-land techniques, making advanced detection capabilities essential for modern security teams.
Indicators of Compromise
| File Hash | File Name | Description / Malware Association |
|---|---|---|
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984 | endpointdlp.dll | Backdoor.Mistic |
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc | f.dll | Fake lock screen (Credential stealer) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.