Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Backdoor May be Linked to Ransomware Access Broker

0
Medium
Published: 06/24/2026 (06/24/2026, 13:40:02 UTC)
Source: AlienVault OTX General

Description

Mistic is a stealthy backdoor malware linked to the Woodgnat initial access broker, active since April 2026. It uses sideloading of legitimate Microsoft files to execute payloads in memory without disk writes, enhancing stealth. Mistic includes typical backdoor functions and a self-delete kill switch. It has been observed deployed alongside ModeloRAT, another tool associated with Woodgnat. Targeting is opportunistic across sectors such as insurance, education, IT, and professional services. Woodgnat sells persistent remote access to ransomware affiliates involved with multiple ransomware families. The threat leverages social engineering lures delivered via compromised WordPress sites.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:47:01 UTC

Technical Analysis

Mistic is a newly identified backdoor malware deployed since April 2026, potentially linked to Woodgnat, an initial access broker that facilitates ransomware operations including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The backdoor employs sideloading techniques using legitimate Microsoft files to execute payloads entirely in memory, avoiding disk writes and increasing stealth. It features typical backdoor capabilities and a self-delete kill switch to evade detection. Mistic has been observed in conjunction with ModeloRAT, a tool developed by Woodgnat. The threat actor Woodgnat operates as an initial access broker, establishing persistent remote access within targeted enterprises and selling this access to ransomware affiliates. The group uses social engineering techniques such as ClickFix, FileFix, and CrashFix lures delivered through compromised WordPress sites. Targeting appears opportunistic across multiple sectors including insurance, education, IT, and professional services.

Potential Impact

The deployment of Mistic backdoor enables attackers to maintain stealthy, persistent remote access within compromised networks. Its in-memory execution and self-delete kill switch reduce the likelihood of detection and forensic analysis. This access facilitates subsequent ransomware operations by affiliates of Woodgnat, potentially leading to data encryption, disruption, and financial loss in targeted organizations across various sectors.

Defensive Guidance

No official patch or remediation is available for Mistic as it is malware rather than a software vulnerability. Detection and mitigation should focus on monitoring for indicators of compromise related to sideloading of legitimate Microsoft files, unusual in-memory execution, and the presence of ModeloRAT or related tools. Organizations should also harden defenses against social engineering attacks, especially those involving compromised WordPress sites. Incident response should include network segmentation and removal of persistent access established by Woodgnat affiliates. Since this is not a cloud service, remediation depends on organizational detection and response capabilities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.security.com/threat-intelligence/new-mistic-backdoor-modelorat"]
Adversary
Woodgnat
Pulse Id
6a3bde32e46aafdb90f9593b
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainmail.authorized-logins.net
domainmueleer.com
domaingrande-luna.top
domainoeannon.com
domainthomphon.com
domainhuman-check.top
domainupdate.update-fall.com
domaincwrtwright.com
domaincarrolc.com
domainw3xasv14culvnqj.top
domainauthorized-logins.net
domainb6w9m2z5x8q1v3k.top
domainrotoa-upda-lo.com
domainsql-updater-service.com
domainupd-domain-goloro.com
domainupdater-worelos.com
domainupscale-kolo.com
domaindefs.updater-worelos.com
domainftps.upd-domain-goloro.com
domainmailes.upd-domain-goloro.com
domainmails.updater-worelos.com
domainnano.upscale-kolo.com
domainphp.authorized-logins.net
domainsss.authorized-logins.net

Hash

ValueDescriptionCopy
hash3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4be
hashfb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a
hash59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712
hashafd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c
hash347a3f5f2ed2f503a22f68c4951c78c7
hash6b8ec32dc76fa3138f00616156962f4f
hashdeb10789274bf903060d700b3472fdf094a14763
hashfd8e880cc32377af08327c9d187f6220c6ac449f
hashb148626849c11dd5b3230632a38a6302
hashe5c4e634b2f443f783cae1b5e8247a1069df0c9f
hash1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984
hashdc96668d007df0a545bf1334e10e80fa
hash48d4872e8463d1ede1b93e3f6a6a8cc8c2cecde3
hash34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc
hash8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235
hashdb972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5
hashf591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e

Ip

ValueDescriptionCopy
ip144.31.53.78
ip198.13.159.44
ip199.91.221.42

Url

ValueDescriptionCopy
urlhttp://thomphon.com/update.msi

Threat ID: 6a3c1d4aeed863c81e3e4800

Added to database: 06/24/2026, 18:09:14 UTC

Last enriched: 07/31/2026, 12:47:01 UTC

Last updated: 08/06/2026, 23:59:30 UTC

Views: 175

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses