Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Broker — Threadlinqs Intelligence
As of 2026-09-01, Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Broker is a high-severity malware threat attributed to Woodgnat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-2277 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Woodgnat · FINANCIAL
Symantec/Broadcom and Zscaler ThreatLabz identified a new stealthy Windows backdoor, Backdoor.Mistic (Zscaler: MLTBackdoor), deployed via DLL sideloading since at least April 2026. It executes
Backdoor.Mistic is delivered by side-loading a malicious version.dll next to the legitimate Microsoft Defender component MpExtMs.exe; the loader hooks GetModuleFileNameW and LoadLibraryW to redirect execution into the actual payload DLL, EndpointDlp.dll, whose filename is deliberately chosen to resemble legitimate Microsoft endpoint-security tooling. In observed intrusions a companion .NET credential stealer displaying a fake login screen (f.dll) was dropped alongside it. Once running, Mistic operates entirely in memory: it can upload, download, move, rename, and delete files, create folders, adjust its C2 check-in interval, execute C2-supplied code with no file written to disk, and load Beacon Object Files (BOFs) to extend its capability set on demand. A built-in kill switch lets the operator terminate and self-delete the implant, removing forensic artifacts and enabling long-term, low-visibility access.
Mistic was observed deployed in close proximity to ModeloRAT, a Python-based RAT attributed to the financially motivated initial access broker Woodgnat (publicly also tracked as KongTuke, 404 TDS, Chaya_002, LandUpdate808, and TAG-124), which has been active since at least May 2024. Woodgnat's business model is to establish durable, stealthy enterprise access and sell it to ransomware affiliates rather than deploy a final payload itself; it has been publicly linked to Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta, and Symantec separately observed ModeloRAT infections followed by Qilin ransomware deployment. Delivery has evolved through a family of social-engineering pretexts the group iterates on: ClickFix (fake error/CAPTCHA prompts, early 2025), FileFix (Windows File Explorer address-bar manipulation, mid-2025), CrashFix (deliberately crashing the browser and offering a fake fix, flagged by Huntress in January 2026), a DNS-based staging variant disclosed by Microsoft in February 2026 that performs DNS lookups as a lightweight signaling/staging channel, and, from April 2026 onward, fake Microsoft Teams messages impersonating IT helpdesk staff (a pivot documented by Rapid7/ReliaQuest in May 2026). All variants ultimately deliver PowerShell that starts the infection chain. Woodgnat also operates a traffic-distribution system (TDS) built on compromised WordPress sites, and its wider toolkit includes a WinPython carrier, Node.exe for attacker JavaScript, finger.exe for retrieving obfuscated payloads, a malicious 'NexShield' Chrome extension, the GateKeeper .NET payload, and the MintsLoader and D3F@ck commodity loaders. Persistence is redundant: run-key entries masquerading as legitimate remote-access software (AnyDesk, Splashtop), startup-folder shortcuts, VBScript launchers, and scheduled tasks. C2 for the ModeloRAT side of the toolkit uses RC4-encrypted traffic over multiple independent, separately hosted C2 paths; non-domain-joined victims receive a heavily obfuscated variant that uses a domain-generation algorithm to cycle fresh C2 domains weekly, and exfiltration is performed over HTTP using curl.exe. Mistic has been observed targeting insurance, education, IT, and professional-services organizations in an opportunistic, non-sector-specific pattern consistent with an access broker casting a wide net and evaluating victims for resale value after compromise.
Target sectors: insurance, education, it, professional services
Timeline
- Woodgnat (KongTuke) initial access broker operations first tracked as active.
- KongTuke begins using ClickFix fake-error/CAPTCHA prompts to trick users into running PowerShell that delivers ModeloRAT.
- FileFix variant observed, manipulating the Windows File Explorer address bar to execute malicious commands.
- Huntress flags ModeloRAT delivered via a new CrashFix variant that deliberately crashes the victim's browser and offers a fake fix.
- Microsoft discloses a DNS-based ClickFix attack variant using DNS lookups as a lightweight staging/signaling channel.
- Backdoor.Mistic first observed deployed in the wild via DLL sideloading (MpExtMs.exe loading version.dll, which loads EndpointDlp.dll).
- KongTuke begins using fake Microsoft Teams messages impersonating IT helpdesk staff to trigger the infection chain.
- Rapid7/ReliaQuest report the group's pivot to Microsoft Teams-based social engineering.
- Zscaler ThreatLabz observes a multi-stage ClickFix chain delivering Mistic, which it tracks as MLTBackdoor.
- Symantec/Broadcom Threat Hunter Team publishes 'Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker,' detailing IOCs and the ModeloRAT/Woodgnat linkage.
- Wide security-press coverage (BleepingComputer, The Hacker News, SecurityAffairs, HelpNetSecurity, CSO Online, and others) links Mistic to KongTuke/Woodgnat and the ransomware affiliates it supplies.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1584.006, T1204.004, T1059.001, T1547.001, T1053.005, T1574.001, T1036, T1684.001, T1027, T1140