Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mistic Backdoor Tied to KongTuke in Recent Cyber Campaigns

Mistic Backdoor Tied to KongTuke in Recent Cyber Campaigns

Posted on June 25, 2026 By CWS

A newly detected backdoor, named Mistic, has surfaced in attacks suspected to have financial motives, targeting sectors such as insurance, education, IT, and professional services since April 2026. This stealthy malware, identified by Symantec and Carbon Black, is linked to an initial access broker known as KongTuke, which is associated with several aliases including 404 TDS and Woodgnat.

Link to KongTuke and Operating Mechanisms

The Mistic backdoor, also referred to as MLTBackdoor, is deployed alongside ModeloRAT, a Python-based remote access trojan previously connected to KongTuke. According to cybersecurity experts, Mistic executes payloads in memory without creating disk artifacts and features a self-deletion switch, indicating its design for prolonged, low-profile access.

ModeloRAT was initially detected in January 2026 by Huntress in the context of a ClickFix campaign. This campaign involved a malicious Chrome extension disguised as an ad blocker to crash browsers and execute unauthorized commands under the guise of a security check.

Exploitation Through ClickFix Campaigns

The malware’s deployment method involves exploiting ClickFix campaigns, which execute DNS lookups to retrieve subsequent payloads. Microsoft has described these tactics as using DNS as a subtle staging channel. Zscaler ThreatLabz connected Mistic’s usage in ClickFix to ransomware actors aiming to establish initial access for further network penetration.

Recent reports from Broadcom highlight that the malware employs DLL side-loading, using legitimate Microsoft tools to disguise its presence. This enables the backdoor to perform actions such as file manipulation, command execution, and dynamic capability expansion via Beacon Object Files (BOFs).

Broader Implications and Future Outlook

Symantec and Carbon Black emphasize the opportunistic nature of these attacks, where perpetrators target a broad range of organizations to evaluate potential access sales. KongTuke’s operations, which include a traffic distribution system leveraging compromised websites, continue to evolve. Recent tactics involve phishing via fake Microsoft Teams messages to initiate attacks with ModeloRAT.

The sophistication of Mistic and its association with skilled threat actors like Woodgnat underscore the growing trend of custom tools in ransomware operations. While Mistic appears to be developed by access brokers rather than directly by ransomware groups, it highlights the increasingly complex landscape of cyber threats.

The cybersecurity community remains vigilant, monitoring these developments to mitigate risks and protect targeted industries from future incursions.

The Hacker News Tags:backdoor malware, Carbon Black, ClickFix, cyber attacks, Cybersecurity, DLL side-loading, IT security, KongTuke, Mistic backdoor, ModeloRAT, Ransomware, stealthy malware, Symantec

Post navigation

Previous Post: SharkLoader Malware Exploits Fake Software Installers
Next Post: NIST Seeks Feedback on IoT Security Guidelines Update

Related Posts

Malicious Ads Lead to EDR-Disabling Malware via Huawei Driver Malicious Ads Lead to EDR-Disabling Malware via Huawei Driver The Hacker News
GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets GeoServer Exploits, PolarEdge, and Gayfemboy Push Cybercrime Beyond Traditional Botnets The Hacker News
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability The Hacker News
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs The Hacker News
Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa Cyber Criminals Exploit Open-Source Tools to Compromise Financial Institutions Across Africa The Hacker News
Dangerous npm Package Steals macOS Credentials Dangerous npm Package Steals macOS Credentials The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Releases Updates for Critical Security Flaws
  • Gaslight macOS Malware Targets AI Analysis with Prompt Injection
  • WhatsApp Introduces New Security Alerts for Unknown Numbers
  • Curl Update Fixes 25-Year-Old Vulnerability
  • OpenClaw Marketplace Faces AI Agent Security Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Releases Updates for Critical Security Flaws
  • Gaslight macOS Malware Targets AI Analysis with Prompt Injection
  • WhatsApp Introduces New Security Alerts for Unknown Numbers
  • Curl Update Fixes 25-Year-Old Vulnerability
  • OpenClaw Marketplace Faces AI Agent Security Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark