Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Stealthy Mistic backdoor linked to ransomware access broker KongTuke

0
High
Malware
Published: 06/24/2026 (06/24/2026, 10:41:51 UTC)
Source: Bleeping Computer

Description

A new backdoor dubbed Mistic has been observed in financially motivated attacks targeting organizations in the insurance, education, IT, and professional services sectors. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/24/2026, 10:54:22 UTC

Technical Analysis

Mistic is a newly identified backdoor used by the initial access broker KongTuke, active since at least 2024, to facilitate ransomware group intrusions. It is deployed through side-loading a malicious DLL (version.dll) by a legitimate executable (MpExtMs.exe), then loads the main backdoor (EndpointDlp.dll) and a .NET DLL that displays a fake login screen to harvest credentials. Mistic operates stealthily by executing code in memory without touching the disk and includes a kill switch to remove itself. It supports commands for file manipulation, adjusting C2 check intervals, executing code in memory, and self-termination. The malware is part of a complex infection chain involving other KongTuke tools and is designed for long-term, low-visibility access. Researchers from Symantec and Zscaler have analyzed Mistic, noting its ability to load Beacon Object Files (BOFs) to extend functionality. No specific infection vector details or patches have been disclosed.

Potential Impact

Mistic enables attackers to maintain persistent, stealthy access to compromised networks, allowing them to manipulate files, execute arbitrary code in memory, and steal credentials. This facilitates further malicious activities, including ransomware deployment by associated threat groups. Its in-memory execution and self-deletion capabilities hinder detection and forensic analysis, increasing the risk of prolonged undetected intrusions in targeted sectors.

Defensive Guidance

No official patch or remediation guidance is currently available. Organizations should monitor vendor advisories for updates. Given the stealthy nature of Mistic and its use of legitimate executables for side-loading, detection may require advanced behavioral and memory analysis techniques. Incident response teams should focus on identifying indicators of compromise provided by Symantec and Zscaler reports and consider enhancing defenses against DLL side-loading and credential phishing via fake login prompts.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/stealthy-mistic-backdoor-linked-to-ransomware-access-broker-kongtuke/","fetched":true,"fetchedAt":"2026-06-24T10:54:13.005Z","wordCount":878}
Classification
{"confidence":0.8,"severitySource":"heuristic","classifier":"rss-v2"}

Threat ID: 6a3bb755eed863c81eb56d35

Added to database: 06/24/2026, 10:54:13 UTC

Last enriched: 06/24/2026, 10:54:22 UTC

Last updated: 08/06/2026, 13:37:20 UTC

Views: 263

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses