← Back to news

Stealthy Mistic backdoor linked to ransomware access broker KongTuke

BleepingComputer24/06/2026, 10:41
Read full article →

Summary

AI-Generated

Key Points:

  • Mistic backdoor, linked to the KongTuke access broker, is being used in financially motivated attacks targeting various sectors, including insurance and education.
  • The malware enables long-term persistence within compromised networks and has been observed since April 2024, with capabilities to evade detection and maintain a stealthy presence.
  • Security teams should implement robust monitoring for unusual executable launches, particularly those resembling legitimate software, and enhance detection capabilities for memory-based payloads.

Technical Details: Mistic is delivered via side-loading a malicious DLL (version.dll) from a legitimate executable (MpExtMs.exe) and communicates with its C2 infrastructure. It can load Beacon Object Files (BOFs) for extended functionality without leaving a disk footprint.

MITRE ATT&CK Techniques:

  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1218.011 - Signed Binary Proxy Execution: DLL Search Order Hijacking (Execution)
  • T1055.001 - Process Injection: DLL Injection (Execution)
  • T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.