Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Stealthy Mistic backdoor linked to ransomware access broker KongTuke

0
Medium
Vulnerability
Published: 06/24/2026 (06/24/2026, 10:41:51 UTC)
Source: Bleeping Computer

Description

Mistic is a stealthy backdoor linked to the ransomware access broker KongTuke, observed since at least April 2026 in attacks targeting insurance, education, IT, and professional services sectors. It is designed for long-term persistence, running payloads in memory without writing files to disk, and includes a kill switch to self-delete. Mistic is deployed via DLL side-loading and can steal credentials through a fake login screen. It communicates with a command-and-control server to receive commands such as file operations and in-memory code execution. The malware is part of a multi-stage infection chain involving other tools used by KongTuke. No patch or official remediation guidance is currently available.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/24/2026, 10:54:22 UTC

Technical Analysis

Mistic is a newly identified backdoor used by the initial access broker KongTuke, active since at least 2024, to facilitate ransomware group intrusions. It is deployed through side-loading a malicious DLL (version.dll) by a legitimate executable (MpExtMs.exe), then loads the main backdoor (EndpointDlp.dll) and a .NET DLL that displays a fake login screen to harvest credentials. Mistic operates stealthily by executing code in memory without touching the disk and includes a kill switch to remove itself. It supports commands for file manipulation, adjusting C2 check intervals, executing code in memory, and self-termination. The malware is part of a complex infection chain involving other KongTuke tools and is designed for long-term, low-visibility access. Researchers from Symantec and Zscaler have analyzed Mistic, noting its ability to load Beacon Object Files (BOFs) to extend functionality. No specific infection vector details or patches have been disclosed.

Potential Impact

Mistic enables attackers to maintain persistent, stealthy access to compromised networks, allowing them to manipulate files, execute arbitrary code in memory, and steal credentials. This facilitates further malicious activities, including ransomware deployment by associated threat groups. Its in-memory execution and self-deletion capabilities hinder detection and forensic analysis, increasing the risk of prolonged undetected intrusions in targeted sectors.

Mitigation Recommendations

No official patch or remediation guidance is currently available. Organizations should monitor vendor advisories for updates. Given the stealthy nature of Mistic and its use of legitimate executables for side-loading, detection may require advanced behavioral and memory analysis techniques. Incident response teams should focus on identifying indicators of compromise provided by Symantec and Zscaler reports and consider enhancing defenses against DLL side-loading and credential phishing via fake login prompts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/","fetched":true,"fetchedAt":"2026-06-24T10:54:13.005Z","wordCount":878}

Threat ID: 6a3bb755eed863c81eb56d35

Added to database: 06/24/2026, 10:54:13 UTC

Last enriched: 06/24/2026, 10:54:22 UTC

Last updated: 06/24/2026, 13:24:42 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses