HomeSecurityKongTuke team uses new Mistic backdoor

KongTuke team uses new Mistic backdoor

A new and highly sophisticated backdoor called Mistic has caused widespread concern in the cybersecurity community as it is being used in financially motivated attacks against organizations across a variety of industries. According to security researchers, the backdoor has already been detected in incidents involving companies in the insurance, education, IT, and professional services sectors

KongTuke Mystic backdoor

Analysts believe that Mistic is linked to the KongTuke, also known as Woodgnat, a so-called Initial Access Broker (IAB). This is a criminal group that specializes in breaching corporate networks and then selling the access it gains to other cybercriminals, often to gangs ransomware.

The connection to ransomware groups

KongTuke has been active since at least 2024 and has been linked to some of the most well-known ransomware groups of recent years, including Qilin, Rhysida, Akira, Interlock, 8Base, and Black Basta.

The business model of these groups has evolved significantly in recent years. Instead of carrying out the initial stage of the attack themselves, ransomware gangs are buying ready-made access from specialized brokers like KongTuke. This practice has created an entire illegal ecosystem, where different criminal groups take on different stages of an attack.

See also: Ransomware 2026: 49% don't understand the attack before data is stolen

Symantec researchers report that Mistic has been in use since at least April and in one case was deployed shortly after the installation of ModeloRAT , another backdoor that has also been attributed to KongTuke and was distributed via social engineering attacks on Microsoft Teams.

How does the Mystic backdoor work?

The new backdoor has been designed with the main goal of remaining silent and long-term within compromised corporate networks.

In the attacks analyzed by Symantec, the infection chain begins with the execution of a legitimate Windows file, MpExtMs.exe. This executable is used to load a malicious DLL file named version.dll, which acts as a loader for the actual backdoor, known as EndpointDlp.dll.

Graphican backdoor

Experts point out that the naming of the files is not accidental. The names refer to legitimate Microsoft security tools, allowing the malware to go unnoticed and be confused with genuine operating system components.

At the same time, a separate .NET DLL, which displays a fake login screen to the victim with the aim of stealing corporate credentials.

The capabilities of the new backdoor

Once installed, Mistic communicates with the attackers' Command and Control infrastructure and can perform a variety of actions.

Among other things, it has the ability to upload and download files, create and delete folders, move data, modify the frequency of communication with the command server, as well as execute malicious code directly in the system memory.

See also: KDDI breach: Up to 14.22 million email accounts may have been exposed

Particularly worrying is the existence of a self-destruct mechanism, which allows the backdoor to delete itself and its traces from the compromised system when its operators deem it necessary.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A malware designed for secrecy

Symantec describes Mistic as an extremely “silent” cyberespionage and persistent access tool. The malware executes payloads directly in memory, without creating files on disk, significantly reducing the chances of detection by traditional protection systems.

Additionally, according to Zscaler, Mistic can load Beacon Object Files (BOFs), small programs written in C that run entirely in memory. This technique is widely used in Red Team tools like Cobalt Strike because it leaves minimal digital footprints.

Researchers also found that Mistic was distributed through a complex, attack ClickFix , confirming that attackers are now leveraging a combination of social engineering tools and advanced obfuscation techniques.

KongTuke team uses new Mistic backdoor

A new trend in ransomware attacks

The emergence of Mistic highlights a broader shift in the cyberthreat landscape. Early access groups are no longer relying solely on publicly available tools, but are developing custom malware specifically designed for persistent and silent penetration into corporate environments.

See also: LastPass: Data breach via Klue supply chain attack

For businesses, this development is yet another reminder that modern ransomware attacks begin long before files are encrypted. Often preceded by a long period of invisibility in the network, during which the attackers collect credentials, map critical systems and prepare the ground for a future large-scale attack.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS