Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mistic Backdoor Tied to KongTuke in Recent Cyber Campaigns

Mistic Backdoor Tied to KongTuke in Recent Cyber Campaigns

Posted on June 25, 2026 By CWS

A newly detected backdoor, named Mistic, has surfaced in attacks suspected to have financial motives, targeting sectors such as insurance, education, IT, and professional services since April 2026. This stealthy malware, identified by Symantec and Carbon Black, is linked to an initial access broker known as KongTuke, which is associated with several aliases including 404 TDS and Woodgnat.

Link to KongTuke and Operating Mechanisms

The Mistic backdoor, also referred to as MLTBackdoor, is deployed alongside ModeloRAT, a Python-based remote access trojan previously connected to KongTuke. According to cybersecurity experts, Mistic executes payloads in memory without creating disk artifacts and features a self-deletion switch, indicating its design for prolonged, low-profile access.

ModeloRAT was initially detected in January 2026 by Huntress in the context of a ClickFix campaign. This campaign involved a malicious Chrome extension disguised as an ad blocker to crash browsers and execute unauthorized commands under the guise of a security check.

Exploitation Through ClickFix Campaigns

The malware’s deployment method involves exploiting ClickFix campaigns, which execute DNS lookups to retrieve subsequent payloads. Microsoft has described these tactics as using DNS as a subtle staging channel. Zscaler ThreatLabz connected Mistic’s usage in ClickFix to ransomware actors aiming to establish initial access for further network penetration.

Recent reports from Broadcom highlight that the malware employs DLL side-loading, using legitimate Microsoft tools to disguise its presence. This enables the backdoor to perform actions such as file manipulation, command execution, and dynamic capability expansion via Beacon Object Files (BOFs).

Broader Implications and Future Outlook

Symantec and Carbon Black emphasize the opportunistic nature of these attacks, where perpetrators target a broad range of organizations to evaluate potential access sales. KongTuke’s operations, which include a traffic distribution system leveraging compromised websites, continue to evolve. Recent tactics involve phishing via fake Microsoft Teams messages to initiate attacks with ModeloRAT.

The sophistication of Mistic and its association with skilled threat actors like Woodgnat underscore the growing trend of custom tools in ransomware operations. While Mistic appears to be developed by access brokers rather than directly by ransomware groups, it highlights the increasingly complex landscape of cyber threats.

The cybersecurity community remains vigilant, monitoring these developments to mitigate risks and protect targeted industries from future incursions.

The Hacker News Tags:backdoor malware, Carbon Black, ClickFix, cyber attacks, Cybersecurity, DLL side-loading, IT security, KongTuke, Mistic backdoor, ModeloRAT, Ransomware, stealthy malware, Symantec

Post navigation

Previous Post: SharkLoader Malware Exploits Fake Software Installers
Next Post: NIST Seeks Feedback on IoT Security Guidelines Update

Related Posts

Shield Your SaaS from Bot Threats with SafeLine WAF Shield Your SaaS from Bot Threats with SafeLine WAF The Hacker News
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading The Hacker News
New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves The Hacker News
Cisco Fixes Critical Flaws in Identity and Webex Services Cisco Fixes Critical Flaws in Identity and Webex Services The Hacker News
SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities The Hacker News
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Curl Update Fixes 25-Year-Old Vulnerability
  • OpenClaw Marketplace Faces AI Agent Security Threats
  • NIST Seeks Feedback on IoT Security Guidelines Update
  • Mistic Backdoor Tied to KongTuke in Recent Cyber Campaigns
  • SharkLoader Malware Exploits Fake Software Installers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Curl Update Fixes 25-Year-Old Vulnerability
  • OpenClaw Marketplace Faces AI Agent Security Threats
  • NIST Seeks Feedback on IoT Security Guidelines Update
  • Mistic Backdoor Tied to KongTuke in Recent Cyber Campaigns
  • SharkLoader Malware Exploits Fake Software Installers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark