Woodgnat
Woodgnat, also known as KongTuke, is a financially motivated cybercrime threat actor assessed to operate primarily as an initial access broker rather than a state-sponsored group. Active since at least May 2024, the group establishes durable remote access in enterprise environments and sells that access to ransomware affiliates and other attackers. It has been publicly linked to ransomware ecosystems including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. Woodgnat’s targeting is described as largely opportunistic. Reported victims span the insurance, education, IT, and professional services sectors, and reporting also mentions schools and insurance firms. The group is associated with the deployment of ModeloRAT, a Python-based remote access trojan, and with the backdoor Mistic, also tracked by Zscaler as MLTBackdoor. In at least one intrusion, Mistic and ModeloRAT were used together. The actor is known for social-engineering-driven initial access. Reported delivery methods include compromised WordPress sites used to serve fake technical alerts and browser-based lures, including ClickFix, FileFix, and CrashFix, that trick users into copying, pasting, or executing malicious PowerShell commands. Since around April 2026, the group has also used external Microsoft Teams messages impersonating IT helpdesk or support personnel to persuade victims to run malicious commands. Observed tradecraft includes multi-stage PowerShell infection chains, DLL sideloading, in-memory execution, credential theft using fake login prompts, reconnaissance with native Windows tools, and use of legitimate utilities including curl, reg.exe, net.exe, PowerShell, certutil, and WMIC. Mistic has been described as a stealthy persistence mechanism that can manage files, execute code received from command-and-control directly in memory, adjust beaconing frequency, and self-delete via a kill switch. Symantec also reported that Woodgnat profiles compromised machines to determine their value and whether access can be sold.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Insurance
- Software & Services
- Academia & Research
Tradecraft
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
Observables
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker activity using Backdoor.Mistic and ModeloRAT to infiltrate corporate networks and sell access to ransomware operators.
Financially motivated initial access broker that establishes durable remote access in enterprise environments and sells that access to ransomware affiliates and other attackers. Recently associated with the Mistic backdoor, ModeloRAT, and the CrashFix ClickFix campaign.
Financially motivated cybercrime group operating since at least May 2024 that compromises networks to establish stealthy access and then sells that access to ransomware affiliates and other criminal groups. It uses Mistic and ModeloRAT, compromises WordPress sites, injects JavaScript, employs ClickFix, FileFix, CrashFix, and fake Microsoft Teams helpdesk lures, and conducts reconnaissance, credential theft, and persistence establishment.
Initial access broker active since at least May 2024, linked to multiple ransomware groups and using Mistic RAT and previously ModeloRAT to compromise organizations and sell access.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.