Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading — Woodgnat/KongTuke Access Broker — Threadlinqs Intelligence
As of 2026-07-01, Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading — Woodgnat/KongTuke Access Broker is a high-severity malware threat attributed to Woodgnat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 51 indicators of compromise.
Threat ID: TL-2026-1038 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Woodgnat · FINANCIAL
Mistic (aka Backdoor.Mistic, tracked by Zscaler as MLTBackdoor) is a fileless, in-memory backdoor that sideloads a malicious EndpointDlp.dll through the legitimate Microsoft executable MpExtMs.exe to
Backdoor.Mistic (publicly documented by Symantec's Threat Hunter Team on 2026-06-24/25 and originally tracked by Zscaler as MLTBackdoor) has been deployed since April 2026 against organizations in insurance, education, IT, and professional-services sectors in opportunistic, financially motivated intrusions. The infection chain begins with social-engineering lures delivered via compromised WordPress sites acting as a traffic distribution system (TDS), or via fake IT-helpdesk messages sent through Microsoft Teams (observed May 2026). Woodgnat/KongTuke has iterated its lure technique over time: ClickFix (early 2025, fake CAPTCHA/error prompts tricking victims into pasting scripts into the Windows Run dialog), FileFix (mid-2025, command execution via the Windows File Explorer address bar), and CrashFix (early 2026), in which a malicious Chrome extension named NexShield (masquerading as an ad blocker) deliberately crashes the victim's browser and presents a fake 'security scan' fix that runs attacker-supplied PowerShell.
Once a victim executes the PowerShell stage, the chain downloads a portable WinPython (WPy64-31401) environment used to run ModeloRAT, a Python-based remote access trojan believed to be co-developed by Woodgnat with ransomware affiliates (first identified by Huntress in January 2026 via a CrashFix variant tied to Qilin activity). ModeloRAT performs deep reconnaissance and credential harvesting using living-off-the-land binaries (net.exe, curl, certutil, WMIC, reg.exe) alongside commodity loaders such as MintsLoader and D3F@ck Loader, and a .NET payload dubbed GateKeeper.
Mistic itself is deployed via DLL sideloading: the legitimate Microsoft executable MpExtMs.exe is used to load a loader DLL, version.dll, which hooks the Windows API functions GetModuleFileNameW and LoadLibraryW to redirect execution to the malicious payload EndpointDlp.dll — named and structured to resemble genuine Microsoft endpoint-security components. The backdoor runs entirely in memory with no files written to disk, supports loading Beacon Object Files (BOFs) for dynamic capability expansion, and communicates over RC4-encrypted C2 traffic. It supports file upload/download, file move/rename/delete, folder creation, adjustable C2 check-in/poll intervals, and remote in-memory code execution, and includes a built-in kill switch that lets it erase itself once access has been sold or is no longer needed — directly undermining static file-based detection and forensic recovery.
Persistence is established redundantly via HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries disguised as legitimate remote-access software (AnyDesk, Splashtop, 'Comms'), Startup-folder shortcuts, VBScript launchers, and scheduled tasks. Post-compromise activity observed alongside Mistic and ModeloRAT includes domain enumeration via net.exe, Kerberoasting of service principal names, PowerShell-based host/service inventory, Active Directory querying, screenshot capture, and a secondary .NET credential-harvesting DLL (f.dll) that presents a fake Windows lock-screen to capture user credentials in cleartext.
Woodgnat/KongTuke is a financially motivated initial-access broker rather than a ransomware operator: its objective is to establish highly durable footholds inside victim networks and sell that access to ransomware affiliates and other criminal buyers. It has been publicly linked to Qilin, Akira, Rhysida, Black Basta, Interlock, and 8Base ransomware operations. DNS-based staging/signaling has also been observed as a lightweight alternative channel for payload retrieval and C2 tasking, complementing the WordPress-TDS and Teams-phishing delivery vectors.
Weaknesses (CWE)
CWE-506, CWE-434, CWE-1021
Target sectors: insurance, education, information technology, professional services
Target regions: Unknown / opportunistic global targeting
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 51 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1189, T1059.001, T1204.004, T1204.002, T1059.006, T1059.005, T1053.005, T1547.001, T1053.005